Spy Trojan

About “Trojan-Spy.Win32.SpyEyes.eut” infection

Malware Removal

The Trojan-Spy.Win32.SpyEyes.eut is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.SpyEyes.eut virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan-Spy.Win32.SpyEyes.eut?


File Info:

name: FB83C077915DFD908ACD.mlw
path: /opt/CAPEv2/storage/binaries/4be0dabf16224167fd40928f0e3f3d1e9be2aa625ed3ca197c5756fdadbb4f4e
crc32: C8710BE0
md5: fb83c077915dfd908acd3501063d032d
sha1: c82345cd71aecd9a04b70f2c0eaf21960158116a
sha256: 4be0dabf16224167fd40928f0e3f3d1e9be2aa625ed3ca197c5756fdadbb4f4e
sha512: f7afa62667e316d1b5f8fad7f4b72826be6f1e947d4347948eae3b78d0965af40a9e243d740b99cfcbd631c7c769ac5ad54640915839b7b07f1d3659ff499fcc
ssdeep: 3072:MQCnEQW4bvtkxqnqwynTfy0jwYp2N1xK7:vkllDyTfy0kw2N1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4B3024FBB7ECE12D27E893110CAC6318554FC6D146902271AB4776F9DB3569C26C83B
sha3_384: 9f5d19a06b6e635bb7003b8bf9b431e6d5f72c19818fc003666f715145b96685b3a0ecc4ebd08e9f7ffe3babea2136b1
ep_bytes: 60be003042008dbe00e0fdff57eb0b90
timestamp: 2007-06-21 10:10:41

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Trojan-Spy.Win32.SpyEyes.eut also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fb83c077915dfd90
ALYacGen:Heur.VIZ.2
CylanceUnsafe
VIPRETrojan.Win32.Kryptik.lbu (v)
SangforTrojan.Win32.SpyEyes.eut
K7AntiVirusTrojan ( 004af95c1 )
AlibabaTrojanSpy:Win32/SpyEyes.36380f17
K7GWTrojan ( 004af95c1 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/S-5f8a72a3!Eldorado
SymantecTrojan.Spyeye
ESET-NOD32a variant of Win32/Kryptik.JAV
APEXMalicious
KasperskyTrojan-Spy.Win32.SpyEyes.eut
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.ZBot.tlrnu
MicroWorld-eScanGen:Heur.VIZ.2
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Spyeyes.Efkl
Ad-AwareGen:Heur.VIZ.2
EmsisoftGen:Heur.VIZ.2 (B)
ComodoMalware@#kk9tneyodtyd
DrWebTrojan.Siggen1.64032
ZillyaTrojan.SpyEyes.Win32.9130
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.YahLover.cc
SophosML/PE-A + Mal/FakeAV-BW
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VIZ.2
JiangminTrojanSpy.SpyEyes.mdl
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=100)
ArcabitTrojan.VIZ.2
ZoneAlarmTrojan-Spy.Win32.SpyEyes.eut
MicrosoftPWS:Win32/Zbot.TQ
AhnLab-V3Spyware/Win32.Zbot.R2551
McAfeeArtemis!FB83C077915D
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
RisingSpyware.SpyEyes!8.4AA (CLOUD)
YandexTrojan.Kryptik!Y1c9oGrSot8
IkarusTrojan.Win32.Spyeye
eGambitGeneric.Malware
FortinetW32/Kryptic!tr
BitDefenderThetaGen:NN.ZexaF.34212.gmKfaqzpohic
AVGWin32:Trojan-gen
Cybereasonmalicious.7915df
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.4360893.susgen

How to remove Trojan-Spy.Win32.SpyEyes.eut?

Trojan-Spy.Win32.SpyEyes.eut removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment