Spy Trojan

Trojan-Spy.Win32.SpyEyes.dxt removal

Malware Removal

The Trojan-Spy.Win32.SpyEyes.dxt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.SpyEyes.dxt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to modify desktop wallpaper
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Behavioural detection: Transacted Hollowing
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Trojan-Spy.Win32.SpyEyes.dxt?


File Info:

name: C502D6D88A7C03B47BF2.mlw
path: /opt/CAPEv2/storage/binaries/4c3767109188408afa74d6c424e967fecfa9ad016313cee3b35481b9cb931001
crc32: E7FF4EB1
md5: c502d6d88a7c03b47bf2cd03e36d9f72
sha1: 94b4eb61f59268100dfa94b0483064afd08e4993
sha256: 4c3767109188408afa74d6c424e967fecfa9ad016313cee3b35481b9cb931001
sha512: b387cfaf36a94bef4c45631ffc6621688508cff63878fb81b53daf043877aa2dcfff1b3e70c2605ede23fafb91d4b8278e5bdf94ebd475e0650626911dfc405c
ssdeep: 6144:LjOP0UuHWbzMnLxPbajqmKeO5fzTAWYpL3OOgcC2TToSYcBO:mcrWbstiEeO5bTvcLkDGToSYc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18544124DA989CA7AF9DC263159FA42902934BC19CCB20ACD26D5B31FD433B11DE8C97D
sha3_384: a4ae1335429b16b7a8e72ae3a0a4019c745b645f9975aa38c8bf02ca53cda42e7ee89219a8a837a8b42e8120e6dd12be
ep_bytes: 60be000043008dbe0010fdff5789e58d
timestamp: 2007-11-05 03:39:03

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Trojan-Spy.Win32.SpyEyes.dxt also known as:

LionicTrojan.Win32.SpyEyes.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.SpySweep.35
MicroWorld-eScanGen:Variant.Bredo.22
FireEyeGeneric.mg.c502d6d88a7c03b4
McAfeeArtemis!C502D6D88A7C
CylanceUnsafe
ZillyaTrojan.SpyEyes.Win32.1987
SangforTrojan.Win32.Crypt.EPACK
K7AntiVirusTrojan ( 004af95c1 )
AlibabaTrojanSpy:Win32/SpyEyes.eb561fba
K7GWTrojan ( 004af95c1 )
Cybereasonmalicious.88a7c0
BitDefenderThetaGen:NN.ZexaF.34232.qmKfaScB8Idc
VirITTrojan.Win32.SpySweep.BJ
CyrenW32/Risk.PGJQ-4363
SymantecTrojan.Spyeye
ESET-NOD32a variant of Win32/Kryptik.JSA
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.dxt
BitDefenderGen:Variant.Bredo.22
NANO-AntivirusTrojan.Win32.SpyEyes.ijlon
SUPERAntiSpywareTrojan.Agent/Gen-Morix
AvastWin32:Malware-gen
TencentWin32.Trojan-spy.Spyeyes.Svgs
Ad-AwareGen:Variant.Bredo.22
EmsisoftGen:Variant.Bredo.22 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionPWS-Spyeye.fa
SophosMal/Generic-R + Mal/FakeAV-BW
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bredo.22
JiangminTrojanSpy.SpyEyes.osi
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1885CD5
GridinsoftRansom.Win32.Zbot.sa
ViRobotTrojan.Win32.Z.Spyeyes.264192
ZoneAlarmTrojan-Spy.Win32.SpyEyes.dxt
MicrosoftTrojan:Win32/EyeStye.AE
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R2551
VBA32Trojan.Zeus.EA.0999
ALYacGen:Variant.Bredo.22
APEXMalicious
RisingRansom.Weenloc!8.519 (CLOUD)
YandexTrojanSpy.SpyEyes!8AvwDzzV9mE
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptic!tr
AVGWin32:Malware-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan-Spy.Win32.SpyEyes.dxt?

Trojan-Spy.Win32.SpyEyes.dxt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment