Spy Trojan

Trojan-Spy.Stealer (A) removal tips

Malware Removal

The Trojan-Spy.Stealer (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Stealer (A) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Spy.Stealer (A)?


File Info:

name: DAD945C2FC1A06D92C2F.mlw
path: /opt/CAPEv2/storage/binaries/ccafeee7d286d874e328f2ad26a6fc1d750a00fb3f212cdbc6331f57f78d1a54
crc32: BE490B21
md5: dad945c2fc1a06d92c2fc8e50964a179
sha1: 50ba669fbdab7a13ab23d6e3dfc4b9d59c27c389
sha256: ccafeee7d286d874e328f2ad26a6fc1d750a00fb3f212cdbc6331f57f78d1a54
sha512: 52e0e5d8d822725cebc8c1c2f4aa5670ced7c200820ddddb97cfa4a2c31edcfb70cb9460fd781d7b6c20232d90ea7af6cd3c097362ff7e7db608626c77d35694
ssdeep: 24576:nXo8x0SIT4JG6qzFYiYJio/GFWhMFdd4zhWu3XQIVIcHbbH6SLT80+Ll3RuQ553y:X/0SIT4JG6qqVnH3XRVIcHbbH6SCl3O
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19EC51A135A8B0D75DDD27BB461CB633AA734EE30CA3A9B7FB608C43959532C46C1A742
sha3_384: ace55e351d630c575b85fca0a09fe04e872fd0e05669724d908580e129ed86040a9aede75cc5585663502498c9119c2d
ep_bytes: 83ec0cc705b843530000000000e88e03
timestamp: 2022-10-01 09:09:34

Version Info:

0: [No Data]

Trojan-Spy.Stealer (A) also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
K7GWTrojan ( 005959c81 )
K7AntiVirusTrojan ( 005959c81 )
CyrenW32/Trojan.HLPX-5019
ESET-NOD32a variant of Win32/Kryptik.HQZO
APEXMalicious
KasperskyVHO:Backdoor.Win32.Convagent.gen
EmsisoftTrojan-Spy.Stealer (A)
IkarusTrojan.Win32.RedlineStealer
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmVHO:Backdoor.Win32.Convagent.gen
GDataWin32.Trojan.PSE.14K7H74
GoogleDetected
AhnLab-V3Trojan/Win.US.R523930
Acronissuspicious
MalwarebytesMalware.AI.731130628
RisingBackdoor.Agent!8.C5D (TFE:5:roJ2h4dAxDP)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/RedLineStealer.D!tr
BitDefenderThetaGen:NN.ZexaF.34698.I!Z@auRn0Yn

How to remove Trojan-Spy.Stealer (A)?

Trojan-Spy.Stealer (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment