Trojan

About “Trojan-PSW.Win32.Stealer.afsk” infection

Malware Removal

The Trojan-PSW.Win32.Stealer.afsk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Stealer.afsk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients

How to determine Trojan-PSW.Win32.Stealer.afsk?


File Info:

name: FD85802B53F7D4E7AC62.mlw
path: /opt/CAPEv2/storage/binaries/8a2634cf6acd9a3467906cdc26af4a0dac4ad513e2d28d274842ee68ac6e2c93
crc32: 47FBDD63
md5: fd85802b53f7d4e7ac62aa8a7831448f
sha1: 98bbf560508952b08bd47e7d2567847bb2a3f044
sha256: 8a2634cf6acd9a3467906cdc26af4a0dac4ad513e2d28d274842ee68ac6e2c93
sha512: 46010d79805962d9fc8ec60a18dbf60bdb36e7e6de186e0f4f50107f76541d7b4dc6c320fae21ac8040332499449609cf18d0cd33f5942a639b7ca3f56191fb0
ssdeep: 24576:34lavt0LkLL9IMixoEgeacnGffmeN2oqGMxGOU8X/5e3z79RWdM8XAFq9MmCS:Skwkn9IMHeacc+elvMxHs/9UdMBaPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19675D00273DE83A0C3725273BE56B755AEBB7C2506B1F59B2FD5093DA920122422F673
sha3_384: bf6c0a1aae82471d3b232075f752b6816e37799e0ca050d18b3fc95338c50b2b7fd62ea4384726b4cc884abe24fc0485
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2022-02-02 08:23:10

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Stealer.afsk also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fd85802b53f7d4e7
McAfeeArtemis!FD85802B53F7
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.b53f7d
CyrenW32/AutoIt.DR.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/PSWTool.MailPassView.E potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CB722
AvastWin32:Malware-gen
ClamAVWin.Malware.Autoit-9780500-0
KasperskyTrojan-PSW.Win32.Stealer.afsk
BitDefenderAIT:Trojan.Nymeria.4778
MicroWorld-eScanAIT:Trojan.Nymeria.4778
TencentWin32.Trojan-qqpass.Qqrob.Egef
Ad-AwareAIT:Trojan.Nymeria.4778
EmsisoftAIT:Trojan.Nymeria.4778 (B)
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen
AviraDR/AutoIt.Gen8
GridinsoftRansom.Win32.Sabsik.sa
ArcabitAIT:Trojan.Nymeria.D12AA
GDataAIT:Trojan.Nymeria.4778 (2x)
AhnLab-V3Malware/Win32.Generic.C4192480
VBA32TrojanPSW.Stealer
ALYacAIT:Trojan.Nymeria.4778
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3616357514
APEXMalicious
eGambitUnsafe.AI_Score_97%
FortinetAutoIt/Agent.OZU!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-PSW.Win32.Stealer.afsk?

Trojan-PSW.Win32.Stealer.afsk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment