Trojan

Trojan-PSW.Win64.Stealer.gj removal guide

Malware Removal

The Trojan-PSW.Win64.Stealer.gj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win64.Stealer.gj virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win64.Stealer.gj?


File Info:

name: 7C6C9BAC17538636833E.mlw
path: /opt/CAPEv2/storage/binaries/c8056a303f97ec2f28373963b3fa839c8e95d8935997f9adf9546df923e913ef
crc32: 48082FD7
md5: 7c6c9bac17538636833e16e3471955ab
sha1: 6cd1dd83545e9431960b15a2bf262c0a3cc2f37c
sha256: c8056a303f97ec2f28373963b3fa839c8e95d8935997f9adf9546df923e913ef
sha512: 93ab35d0e4f2581d38853a5a9f70852ee1892d16dbf7cc6e762ecc2473af43040e626094ea1e04ee136296dc9acaa315a1c7084af1e083af749466aa9c6c337b
ssdeep: 98304:DecRkvRv7CAY55plXHssrtIxMzWdxD3dQ/5XYJ3M/7b1HTeTXgTHk:Dbc7TYnBY3W/J/7xz4XOHk
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1675633B744C53BDAC0B5EBFD5D1A100884A06E13460645B5F1AF59BBAFDC4ADC3A2BC2
sha3_384: 6bb94d2e3e14de49bedb70cf10e67125c79105953fe8a63cff2e156a2a06e9d2bb9ca617da7edec5d84299e62295980b
ep_bytes: e88201000041524989e24152498b7210
timestamp: 2022-11-13 17:39:47

Version Info:

0: [No Data]

Trojan-PSW.Win64.Stealer.gj also known as:

LionicTrojan.Win64.Agentb.trtl
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.63731774
FireEyeGeneric.mg.7c6c9bac17538636
McAfeeArtemis!7C6C9BAC1753
MalwarebytesSpyware.PasswordStealer
SangforTrojan.Win64.Agent.Vj6r
AlibabaTrojanPSW:Win64/Stealer.1ee08251
Cybereasonmalicious.3545e9
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win64.Stealer.gj
BitDefenderTrojan.GenericKD.63731774
AvastWin64:Evo-gen [Trj]
TencentWin64.Trojan-QQPass.QQRob.Czlw
McAfee-GW-EditionBehavesLike.Win64.Trickbot.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1235344
MicrosoftTrojan:Script/Wacatac.H!ml
GDataTrojan.GenericKD.63731774
AhnLab-V3Trojan/Win.Agent.R534769
Acronissuspicious
MAXmalware (ai score=89)
RisingStealer.Agent!8.C2 (CLOUD)
AVGWin64:Evo-gen [Trj]

How to remove Trojan-PSW.Win64.Stealer.gj?

Trojan-PSW.Win64.Stealer.gj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment