Trojan

Trojan-PSW.Win32.Stealer.afpu removal instruction

Malware Removal

The Trojan-PSW.Win32.Stealer.afpu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Stealer.afpu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan-PSW.Win32.Stealer.afpu?


File Info:

name: D51D30EC302A18D5193A.mlw
path: /opt/CAPEv2/storage/binaries/ff901255e611e578028555c8025d08622107187bdee30535c489748d8866efc5
crc32: C98C1B88
md5: d51d30ec302a18d5193a84826111f79b
sha1: 707f2c832536e565c17673b46ea38020a3885e07
sha256: ff901255e611e578028555c8025d08622107187bdee30535c489748d8866efc5
sha512: d957852fd3c2b4b78d084b2ac62cad7ede961a8f0c7890e3a574cae42153c4f4ba5a29a5e39a090dbcb02bc6c149f19d89d3ee2c4319710b7341d3f9eb351214
ssdeep: 1536:yz7XUZUxIT34IFH0ZoX2BztMJOhahW9v:JMImL9v
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A34301F5DB970A07C6681C3444C31E1B86B97F00850DAE378A7D6ACAB2A445B7C6973E
sha3_384: 73b9704051217f3bb70fd994517161a4b5d38deb1333bc60678a606a312638cdce2b55d715e962b8f62a3a43540aaf5d
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-PSW.Win32.Stealer.afpu also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
FireEyeGeneric.mg.d51d30ec302a18d5
McAfeeGenericRXQS-VX!D51D30EC302A
CylanceUnsafe
SangforRansom.Win32.FileCryptor.MAK!MTB
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/FileCryptor.07ed0135
K7GWTrojan ( 0058ac911 )
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderThetaAI:Packer.456DD6081E
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
TrendMicro-HouseCallTROJ_FRS.0NA103B222
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-PSW.Win32.Stealer.afpu
BitDefenderGen:Variant.Ransom.Sugar.17
AvastWin32:Malware-gen
TencentWin32.Trojan-qqpass.Qqrob.Wopp
Ad-AwareGen:Variant.Ransom.Sugar.17
SophosMal/Generic-S
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionGenericRXQS-VX!D51D30EC302A
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
IkarusTrojan-Ransom.FileCrypter
GDataGen:Variant.Ransom.Sugar.17
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
GridinsoftRansom.Win32.AI.sa
ViRobotTrojan.Win32.Z.Filecoder.59392.E
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
VBA32BScope.TrojanRansom.Cryptor
ALYacGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
MalwarebytesRansom.Encoded01
APEXMalicious
RisingRansom.Cryptor!8.10A9 (CLOUD)
YandexTrojan.Filecoder!kxBVJWKPBlE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.139762548.susgen
FortinetW32/Filecoder.OJD!tr.ransom
AVGWin32:Malware-gen
Cybereasonmalicious.c302a1
PandaTrj/Genetic.gen

How to remove Trojan-PSW.Win32.Stealer.afpu?

Trojan-PSW.Win32.Stealer.afpu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment