Trojan

What is “Trojan-PSW.Win32.Stealer.xht”?

Malware Removal

The Trojan-PSW.Win32.Stealer.xht is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Stealer.xht virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers

How to determine Trojan-PSW.Win32.Stealer.xht?


File Info:

name: C2821C46D93695DA5E8E.mlw
path: /opt/CAPEv2/storage/binaries/d56e752adcb7e0143a7113de272f5ee0725010d7b3a8c83d1617646a33bb7747
crc32: AA9D3C32
md5: c2821c46d93695da5e8ed9bfe1327422
sha1: b1b438e0c8614d400540165c6805bdcdfe89a799
sha256: d56e752adcb7e0143a7113de272f5ee0725010d7b3a8c83d1617646a33bb7747
sha512: ca958f94a5272ea621f7819d7d07dddac182b141e4dcc2d820c0121155b7dc6de2441fb94f1cdc574f07ec7381da773c869df0efa261b1bf667a52da6d63a65a
ssdeep: 24576:w4lavt0LkLL9IMixoEgeaNMOOyFk4q8yLUhdy6HjuSNJIFHH1Yaq9MmCS:nkwkn9IMHeaNBq8yLUhbjuLFn1/aPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E875E00373ED83A1C3725273BA26B755AEBB7C290661F59B2FD9053DE920022521F673
sha3_384: 22531538aa56b117390af1314cf3ef5188a0781e60c78222cd2555823f704c4ac3576653db5f2c05dd478f7ae993b118
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2021-12-05 18:46:45

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Stealer.xht also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.7867
MicroWorld-eScanAIT:Trojan.Nymeria.4778
FireEyeGeneric.mg.c2821c46d93695da
McAfeeArtemis!C2821C46D936
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.6d9369
CyrenW32/AutoIt.DR.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/PSWTool.MailPassView.E potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CL621
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Stealer.xht
BitDefenderAIT:Trojan.Nymeria.4778
NANO-AntivirusTrojan.Win32.Stealer.jjekhc
AvastWin32:Malware-gen
TencentWin32.Trojan-qqpass.Qqrob.Sxdy
Ad-AwareAIT:Trojan.Nymeria.4778
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftAIT:Trojan.Nymeria.4778 (B)
AviraDR/AutoIt.Gen8
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataAIT:Trojan.Nymeria.4778 (2x)
AhnLab-V3Malware/Win32.Generic.C4192480
ALYacAIT:Trojan.Nymeria.4778
MAXmalware (ai score=83)
VBA32TrojanPSW.Stealer
MalwarebytesMalware.AI.3616357514
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Agent.OZU!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-PSW.Win32.Stealer.xht?

Trojan-PSW.Win32.Stealer.xht removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment