Trojan

Trojan-PSW.Win32.Stealer.xqg removal instruction

Malware Removal

The Trojan-PSW.Win32.Stealer.xqg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Stealer.xqg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win32.Stealer.xqg?


File Info:

name: E13C06650913ACD56FD2.mlw
path: /opt/CAPEv2/storage/binaries/e15791354eb24d811322afec27ac96dd9a14664f23baffc4d6d2419c4726fae7
crc32: FE09E24D
md5: e13c06650913acd56fd2e1683b2aebb9
sha1: 0a257c1919a593ce11bc8b7a9c4d27c71f3f1c11
sha256: e15791354eb24d811322afec27ac96dd9a14664f23baffc4d6d2419c4726fae7
sha512: c0e8e8ace8764cddcf78215cfaaff5275b0d411cd8527fd7486c0a3d3d2d70e766f73057ee5df93bca3f1ddba6f7204d5b1b834a92a14fdd06ea1b0ba1f57c38
ssdeep: 6144:HYknnoXHQpWVdrKKJFhIgleVJJ6zk6um6c2ykyuCXN1QVroW:HgHYwpJFhI2eV96ubykyNN1PW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199E4239FEA40CCD5C7152330901BC83AFE256E8B9CFF6D8731C17CB80A7556A9E8046A
sha3_384: b6abbd0ad3a0eddf51daf46253b719315909468e7cc47a0e246b4417ff33461c4ec3bbe2540db767f5fc0f1c24f9206f
ep_bytes: 6801106800e801000000c3c3c564012b
timestamp: 2021-12-04 07:37:00

Version Info:

0: [No Data]

Trojan-PSW.Win32.Stealer.xqg also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.47614453
FireEyeGeneric.mg.e13c06650913acd5
McAfeeGenericRXAA-AA!E13C06650913
CylanceUnsafe
Cybereasonmalicious.919a59
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-PSW.Win32.Stealer.xqg
BitDefenderTrojan.GenericKD.47614453
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47614453
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.jz
EmsisoftTrojan.GenericKD.47614453 (B)
GDataTrojan.GenericKD.47614453
Antiy-AVLTrojan/Generic.ASMalwS.34E60A7
ViRobotTrojan.Win32.Z.Agent.707584.DP
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R455841
BitDefenderThetaGen:NN.ZexaF.34084.RGWaaWgdMDki
MAXmalware (ai score=84)
MalwarebytesMalware.AI.4223989364
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Stealer.xqg?

Trojan-PSW.Win32.Stealer.xqg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment