Spy Trojan

Trojan-Spy.Win32.Stealer.anzj removal tips

Malware Removal

The Trojan-Spy.Win32.Stealer.anzj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.anzj virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • CAPE detected the EnigmaStub malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Harvests cookies for information gathering

How to determine Trojan-Spy.Win32.Stealer.anzj?


File Info:

name: 4BA8A6AF59B167AA45B1.mlw
path: /opt/CAPEv2/storage/binaries/33b18a85c6b49af6f5025ada7db397fad10b6e1d0c25d98b9ac557c3024a2ac4
crc32: 9FDDD103
md5: 4ba8a6af59b167aa45b1c9aae4a8f682
sha1: 414842ce90f8968f397a731e447a4559155f4e6a
sha256: 33b18a85c6b49af6f5025ada7db397fad10b6e1d0c25d98b9ac557c3024a2ac4
sha512: 12b59b8724eeca316cb264d836a13c9016d1cd2ac2a5738cc57016231b684dbb5834d900238446e3bdfa98c236d74b515d76b08218364e81eaeb97bf76cb3283
ssdeep: 196608:qeclZZigEom5TmcP11Ts5Sp1sUHKB3zf1WkSJYVjiQYEyMZZsK:7zam5Xtdskp1gumRvZZsK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBB63312789701BEDD731A79212BA271873835300FA85A7FE7F08DDC5E3A5C0AA65793
sha3_384: e895e75e8d7f5a41d2a1410821f6d24307ace63009083aadf663af7c2a144b2f53d0de120e234b8e7733f80a58fe4d90
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.anzj also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.NanoBot.trQD
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.64237
MicroWorld-eScanTrojan.GenericKD.38199667
FireEyeGeneric.mg.4ba8a6af59b167aa
McAfeeArtemis!4BA8A6AF59B1
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2205396
AlibabaTrojanSpy:Win32/Stealer.1f2d5465
K7GWTrojan ( 005823691 )
K7AntiVirusTrojan ( 005823691 )
CyrenW32/Stealer.S.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_FRS.VSNTL621
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.anzj
BitDefenderTrojan.GenericKD.38199667
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.38199667
ComodoTrojWare.Win32.Agent.vriqk@0
TrendMicroTROJ_FRS.VSNTL621
IkarusTrojan-Spy.Win32.CredStealer
GDataWin32.Trojan-Stealer.CredStealer.MZX0M0
AviraTR/Redcap.hiiyo
MAXmalware (ai score=86)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D246E173
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C4785054
VBA32BScope.TrojanPSW.MSIL.Agensla
ALYacTrojan.GenericKD.38199667
MalwarebytesTrojan.MalPack
APEXMalicious
YandexTrojan.GenAsa!l3ZfBja75G8
SentinelOneStatic AI – Malicious SFX
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
Cybereasonmalicious.e90f89
PandaTrj/CI.A

How to remove Trojan-Spy.Win32.Stealer.anzj?

Trojan-Spy.Win32.Stealer.anzj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment