Spy Trojan

Trojan-Spy.Win32.Stealer.allo removal

Malware Removal

The Trojan-Spy.Win32.Stealer.allo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.allo virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan-Spy.Win32.Stealer.allo?


File Info:

name: AD2E0AFBAFC83F4D3779.mlw
path: /opt/CAPEv2/storage/binaries/c99a60c07685e336f4265cb60bfb756649a483cd2ae696120383246f1f5ed90a
crc32: A71B4AC6
md5: ad2e0afbafc83f4d377903d0ccd758f8
sha1: 21bf68d4299fa0735fdb39e837e41aaa40a3fe49
sha256: c99a60c07685e336f4265cb60bfb756649a483cd2ae696120383246f1f5ed90a
sha512: 7e4dd755e1bdfdb2993229562e724cd2ad4c7256ccb815ec094f96f2f1ce272c05575667a347aeadf86ce7a07a59193bbb3b31d67db0bc0e57094c62152b2a93
ssdeep: 12288:SzxzTDWikLSb4NS7M3K9999dddddddzDdrK9999dddddddzDd/wX9MbmpcyHneay:EDWHSb4NFK9999dddddddzDdrK9999dJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187C4E002F8815472CA213935C929E67164397D201F24CBDBA3D47E6BBA331DDA735BA3
sha3_384: 4dd11f3e5e1b738bf764a6fb788a97f9c9dfb2f829309f8c1993598a53beecee6f15369add2a6928305182895875bf42
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.allo also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.NanoBot.trQD
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.7323
MicroWorld-eScanTrojan.GenericKD.47509459
FireEyeGeneric.mg.ad2e0afbafc83f4d
McAfeeArtemis!AD2E0AFBAFC8
CylanceUnsafe
SangforSpyware.Win32.Stealer.allo
K7AntiVirusTrojan ( 0058949a1 )
AlibabaTrojanSpy:Win32/Stealer.19f64c72
K7GWTrojan ( 0058949a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilCO.34084.Fm2@aOj3Rym
CyrenW32/MSIL_Troj.BUC.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ADLB
TrendMicro-HouseCallTrojanSpy.Win32.STEALER.USASHLA21
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.allo
BitDefenderTrojan.GenericKD.47509459
NANO-AntivirusTrojan.Win32.Stealer.jinvvb
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan-spy.Stealer.Lnek
Ad-AwareTrojan.GenericKD.47509459
SophosMal/Generic-S
Comodofls.noname@0
TrendMicroTrojanSpy.Win32.STEALER.USASHLA21
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftTrojan.GenericKD.47509459 (B)
IkarusTrojan.MSIL.Crypt
GDataMSIL.Trojan.BSE.12B6GLS
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.RedLineSteal.cmlzr
Antiy-AVLTrojan/Generic.ASMalwS.34DAD1B
MicrosoftTrojan:MSIL/StealerPacker!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R449948
ALYacTrojan.GenericKD.47509459
MAXmalware (ai score=84)
VBA32Backdoor.Androm
MalwarebytesTrojan.Crypt.MSIL
APEXMalicious
YandexTrojan.Kryptik!CXxh9IcZkZo
SentinelOneStatic AI – Malicious SFX
FortinetW32/GenKryptik.FNMI!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan-Spy.Win32.Stealer.allo?

Trojan-Spy.Win32.Stealer.allo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment