Spy Trojan

Trojan-Spy.Win32.Stealer.aojd malicious file

Malware Removal

The Trojan-Spy.Win32.Stealer.aojd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.aojd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.aojd?


File Info:

name: C4F2210B95279772A638.mlw
path: /opt/CAPEv2/storage/binaries/71681bbe16231429866cf00e67d4db1824bbc7149a911d848100542e71cb7e9b
crc32: 10616A65
md5: c4f2210b95279772a638ef963482cf32
sha1: d59b908be5743d85ebd36929f86db6e499e5d6c2
sha256: 71681bbe16231429866cf00e67d4db1824bbc7149a911d848100542e71cb7e9b
sha512: dcc08aa2ab39b3a790896cfd4cc6c80d4af4e91ac58eb038eab69c4a3499fb2ac6ca5d6d0b7b21145f23a85607b62e11738d4864a026cd0aadd90a0dcd1f4c0a
ssdeep: 12288:wbvYFYUp7L5++9x95fK/Irhw0jTC85FLPfWwsXDgOmeD7:YvYFYG70+9x9lK/IrfjTC8DfWbXDAs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AE42393DB82C857C934C571EE57EB3894B1BC6D4BA077E230CA351F2CB8361A912667
sha3_384: 28cd4478f73ebb06e45da0143fd0425832c69c57483b66c965415c48924cc3f092e4d9569f1b6fbd4e19983c9051e4db
ep_bytes: 6801406a00e801000000c3c3411bfa34
timestamp: 2021-11-27 16:35:02

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.aojd also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.c4f2210b95279772
McAfeeArtemis!C4F2210B9527
K7AntiVirusTrojan ( 0058b32c1 )
BitDefenderTrojan.GenericKD.38218415
K7GWTrojan ( 0058b32c1 )
Cybereasonmalicious.be5743
ArcabitTrojan.Generic.D2472AAF
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.KJ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.aojd
AlibabaTrojanSpy:Win32/Stealer.e4686600
MicroWorld-eScanTrojan.GenericKD.38218415
Ad-AwareTrojan.GenericKD.38218415
EmsisoftTrojan.GenericKD.38218415 (B)
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_90%
MAXmalware (ai score=87)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan-Stealer.Redline.O14SZ9
BitDefenderThetaGen:NN.ZexaF.34084.RGWaamrpt8bi
ALYacTrojan.GenericKD.38218415
VBA32BScope.TrojanPSW.Racealer
MalwarebytesMalware.Heuristic.1003
TencentWin32.Trojan.Generic.Taoo
IkarusTrojan.Win32.Crypt
FortinetW32/PossibleThreat
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Spy.Win32.Stealer.aojd?

Trojan-Spy.Win32.Stealer.aojd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment