Spy Trojan

Should I remove “Trojan-Spy.Win32.Stealer.aofp”?

Malware Removal

The Trojan-Spy.Win32.Stealer.aofp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.aofp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.aofp?


File Info:

name: 4925CFBEA9E59540B5AC.mlw
path: /opt/CAPEv2/storage/binaries/a81f7500dff581a288b5967b5bfd01aa27b0360cd6cf05a32d1a44421ff6ee5b
crc32: 4F32064E
md5: 4925cfbea9e59540b5ac2ce4696915a7
sha1: 9dd4f03b4dbd8794ac780620f9758ec002cb5ecd
sha256: a81f7500dff581a288b5967b5bfd01aa27b0360cd6cf05a32d1a44421ff6ee5b
sha512: e8b2359f522824141e6e10487c945ae310c8c832937c9ca84c4e98c703ae5eca1b2080c792d5207d9992be5c41f517e8ef38ab40eda95d017c855c90998b61d5
ssdeep: 24576:Zxm+a7IYsBRSGhTlBUy4yOqPm3OBTJi4QW+:3Da7HeBO9qPm3OBT84t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19925AE80F34CED8BC01A0573E86EC31010B4576D91AA9A5F2196731BD9E738E276BF9D
sha3_384: 5882f28f0784897142ddc2d650167e24c3516f4a77d54d820592a16620080cd1ba904f052295f5daf40a44dbb4e8bede
ep_bytes: eb05fe3a6f5e9350eb0522abd978a5e8
timestamp: 2093-04-02 13:50:31

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Platform SE binary
FileVersion: 8.0.3110.11
Full Version: 1.8.0_311-b11
InternalName: mlib_image
LegalCopyright: Copyright © 2021
OriginalFilename: mlib_image.dll
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.3110.11
Translation: 0x0000 0x04b0

Trojan-Spy.Win32.Stealer.aofp also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Stealer.l!c
MicroWorld-eScanTrojan.GenericKD.47579089
FireEyeGeneric.mg.4925cfbea9e59540
McAfeeArtemis!4925CFBEA9E5
MalwarebytesTrojan.MalPack
K7AntiVirusTrojan ( 0058b79c1 )
K7GWTrojan ( 0058b79c1 )
Cybereasonmalicious.b4dbd8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CS
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.aofp
BitDefenderTrojan.GenericKD.47579089
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.97 (RDMK:eg7r9+AH9PYxOCaA5ijSsw)
Ad-AwareTrojan.GenericKD.47579089
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen3.7913
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftExploit:Win32/ShellCode!ml
GDataTrojan.GenericKD.47579089
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.@q3@aiUXk!fi
ALYacTrojan.GenericKD.47579089
MAXmalware (ai score=83)
VBA32BScope.Trojan.Tiggre
CylanceUnsafe
IkarusTrojan.Win32.Obsidium
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-Spy.Win32.Stealer.aofp?

Trojan-Spy.Win32.Stealer.aofp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment