Spy Trojan

Trojan-Spy.Win32.Stealer.akbi malicious file

Malware Removal

The Trojan-Spy.Win32.Stealer.akbi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.akbi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Possible date expiration check, exits too soon after checking local time
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.akbi?


File Info:

name: 3A9F691826A547A96EEF.mlw
path: /opt/CAPEv2/storage/binaries/c8503f3d32aff5f4d1e885fbf48d1c658c7129b6d8fbd6cb6126e3fb0db94668
crc32: C654165F
md5: 3a9f691826a547a96eef4baf0cacfdb5
sha1: 1d23237bc0f0dd7d45d3be83250351c217b18602
sha256: c8503f3d32aff5f4d1e885fbf48d1c658c7129b6d8fbd6cb6126e3fb0db94668
sha512: c2c5985607344f3c9ce3e238e71c610eeb6b8b5d42d3fd594f43947b2c51e083ace9d430c67ad6559b7c87cc2f75241a78d521a27fafe38e9c570ce58f2ac093
ssdeep: 24576:SXeO4z9uGU/BMlIqtlB1bf+etWM9Re0nNc7lsIHR2YrNBEmnajy:SOONFyw2c7lsmTrXtam
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC4533F14B0174C9CABBAB76EF2D7E113A776375B4E590BE9024CB242F617A25253830
sha3_384: 7ea6eea0450116837c887ca782535352f6e4b625f8ef27b558985556c4da91d18348125113ee4a41c0b9133def1e4a8b
ep_bytes: 558bec83c4f0b800104000e801000000
timestamp: 2067-06-06 07:37:16

Version Info:

Translation: 0x0000 0x04b0
Comments: rHFJrVO
CompanyName: psIzCrSuW
FileDescription: rHFJrVO
FileVersion: 0.38.18.40
InternalName: jNvSDmh.exe
LegalCopyright: Copyright © 2021 psIzCrSuW
LegalTrademarks:
OriginalFilename: jNvSDmh.exe
ProductName: rHFJrVO
ProductVersion: 0.38.18.40
Assembly Version: 0.38.18.40

Trojan-Spy.Win32.Stealer.akbi also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.22467
MicroWorld-eScanTrojan.GenericKD.47474595
McAfeeArtemis!3A9F691826A5
CylanceUnsafe
K7AntiVirusTrojan ( 0055f2201 )
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 0055f2201 )
Cybereasonmalicious.bc0f0d
ArcabitTrojan.Generic.D2D467A3
BitDefenderThetaGen:NN.ZexaF.34294.kz2@amWem0o
CyrenW32/Trojan.FFG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Enigma.DS
Paloaltogeneric.ml
ClamAVWin.Malware.Bulz-9854835-0
KasperskyTrojan-Spy.Win32.Stealer.akbi
BitDefenderTrojan.GenericKD.47474595
AvastWin32:Trojan-gen
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
Ad-AwareTrojan.GenericKD.47474595
EmsisoftTrojan.GenericKD.47474595 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.3a9f691826a547a9
SophosMal/Generic-S
IkarusPUA.EnigmaProtector
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1142094
Antiy-AVLTrojan/Generic.ASBOL.C669
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.47474595
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.GenericKD.47474595
MAXmalware (ai score=83)
VBA32Trojan.Zpevdo
MalwarebytesTrojan.Downloader
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.AK!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan-Spy.Win32.Stealer.akbi?

Trojan-Spy.Win32.Stealer.akbi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment