Spy Trojan

Trojan-Spy.Win32.Stealer.amum removal guide

Malware Removal

The Trojan-Spy.Win32.Stealer.amum is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.amum virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • CAPE detected the RedLine malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.amum?


File Info:

name: 009C82F66E07F3A58E46.mlw
path: /opt/CAPEv2/storage/binaries/8f373d62df45cf52ac4c5f3cea802422b4e06ee3bef9ad7a95c22ac7383917fd
crc32: 2862F5EA
md5: 009c82f66e07f3a58e46484b00aabcdd
sha1: a6336db06bba9a8c078ccf108a1d3f5e812bc700
sha256: 8f373d62df45cf52ac4c5f3cea802422b4e06ee3bef9ad7a95c22ac7383917fd
sha512: 6ee2773beeb4cef0aa77381cd32acb7c34f0874f8d2eb60967b4e18f053377dc284b3dfee2302c8e6d8591df9cabe4d208f76f9161d220c18d52ed7fbc320d37
ssdeep: 49152:OXm0z2WGMzGSQl3BlTMC8+dJ229LbkNaQ:OWC2yaBJBNM2dJhN0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17675336F86489E8DE1CA98FD2764F101E04371725FFAA292E13F72224786A07F93D51D
sha3_384: fc002919d235ddbbabc35f4669acd76b145fbceda5d8266879382a643e71d778a5bafae402cb4c01b458fbc0048436c8
ep_bytes: 6801807c00e801000000c3c3802ccf03
timestamp: 2021-12-01 18:13:26

Version Info:

Comments: B5atEZ8J
CompanyName: EJr9Cbq4
FileDescription: NgpcgWXs
FileVersion: 2,11,11,0
InternalName: lo81eyjg
LegalCopyright: WWYNeu6C
OriginalFilename: bcyPDgJz
ProductName: pNtGglFf
ProductVersion: 2,11,11,0
Assembly Version: 2,11,11,0
Translation: 0x0000 0x04b0

Trojan-Spy.Win32.Stealer.amum also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38198367
FireEyeGeneric.mg.009c82f66e07f3a5
McAfeeAgentTesla-FDFF!009C82F66E07
MalwarebytesTrojan.MalPack
SangforTrojan.Win32.Asprotect.NAY
K7AntiVirusTrojan ( 0058b28c1 )
AlibabaTrojanSpy:Win32/Stealer.6f3bf690
K7GWTrojan ( 0058b28c1 )
Cybereasonmalicious.06bba9
CyrenW32/Stealer.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.KO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.amum
BitDefenderTrojan.GenericKD.38198367
AvastWin32:Trojan-gen
TencentWin32.Trojan.Falsesign.Dlc
Ad-AwareTrojan.GenericKD.38198367
SophosMal/Generic-S
DrWebTrojan.PWS.Steam.23240
TrendMicroTrojan.Win32.STEALER.USMANL621
McAfee-GW-EditionAgentTesla-FDFF!009C82F66E07
EmsisoftTrojan.GenericKD.38198367 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38198367
JiangminTrojanSpy.Stealer.kjn
AviraTR/Spy.Stealer.ucgtr
KingsoftWin32.Troj.Stealer.am.(kcloud)
GridinsoftTrojan.Heur!.012120B1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R455306
BitDefenderThetaGen:NN.ZexaF.34114.HL2aa8!Zgfli
ALYacTrojan.GenericKD.38198367
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Foreign
TrendMicro-HouseCallTrojan.Win32.STEALER.USMANL621
YandexTrojan.GenAsa!l3ZfBja75G8
IkarusTrojan.Win32.ASProtect
FortinetW32/Asprotect.NAY!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Spy.Win32.Stealer.amum?

Trojan-Spy.Win32.Stealer.amum removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment