Trojan

About “Trojan.Sdter” infection

Malware Removal

The Trojan.Sdter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Sdter virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan.Sdter?


File Info:

name: E5E89BF1EB6226AC8039.mlw
path: /opt/CAPEv2/storage/binaries/28f2ab793d10d51510335add487584df50ac166f414235b5e7f90a3e1609d6bf
crc32: 549B8CE0
md5: e5e89bf1eb6226ac8039b281ac733b01
sha1: 10bd287d7784eb1b51f207142454ea0f8ac35ca2
sha256: 28f2ab793d10d51510335add487584df50ac166f414235b5e7f90a3e1609d6bf
sha512: 6d3810d86bffd28ccad77a4ed4d0d0eadddbc7e01ea13f6f3ed13decd57a1ea78702696389fa0ef9076ae883b858803d8382e36e66789145aab912179dffc1c1
ssdeep: 192:KlApk98m4e0/IDJM/5ZQcvoyne4t/PQ3Pw1CNSluWbiWBNEckxC/U0Sq0edU9:MApc8m4e0LvQak4JI341CNabnkIU0Sqw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAE2716739B0467AC73A8730447EB8B15DB6BF0A7480884EC512F6B68877FD29E1D709
sha3_384: d0da4c985749e12b8e30efcec9534892bac85d400013ba685a3fd705fcb1fd28eff2439ba10e7d92b3ac36264723ec44
ep_bytes: 558bec6aff6888204000685018400064
timestamp: 2006-07-02 14:19:05

Version Info:

0: [No Data]

Trojan.Sdter also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.buX@HPIO3zfb
SkyhighBehavesLike.Win32.Generic.nt
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Heur.buX@HPIO3zfb
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0055c6c71 )
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
VirITTrojan.Win32.Loan.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SOI
APEXMalicious
ClamAVWin.Malware.Loan-10026833-0
KasperskyTrojan-Downloader.Win32.Loan.a
BitDefenderGen:Trojan.Heur.buX@HPIO3zfb
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Loan.ha
EmsisoftGen:Trojan.Heur.buX@HPIO3zfb (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebTrojan.Sdter.40
ZillyaDownloader.Loan.Win32.18
FireEyeGeneric.mg.e5e89bf1eb6226ac
SophosML/PE-A
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDownloader.Loan.h
VaristW32/Heuristic-XEN!Eldorado
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Downloader]/Win32.Loan
Kingsoftmalware.kb.a.993
MicrosoftTrojanDownloader:Win32/Loan.BG!MTB
ArcabitTrojan.Heur.E61E2D
ZoneAlarmTrojan-Downloader.Win32.Loan.a
GDataWin32.Trojan.PSE.PCO3BX
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5605735
VBA32Trojan.Sdter
ALYacGen:Trojan.Heur.buX@HPIO3zfb
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDropper.Agent!1.E3CA (CLASSIC)
YandexTrojan.GenAsa!aOeY2HHrzOs
SentinelOneStatic AI – Malicious PE
MaxSecureDownloader.W32.Loan.a
FortinetW32/Agent.SOI!tr
BitDefenderThetaAI:Packer.D4FE002E1C
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Sdter?

Trojan.Sdter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment