Spy Trojan

Trojan-Spy.Win32.Stealer.aoqv removal

Malware Removal

The Trojan-Spy.Win32.Stealer.aoqv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.aoqv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.aoqv?


File Info:

name: A68A851E1A79CF9806F6.mlw
path: /opt/CAPEv2/storage/binaries/a36c23e7da65bd43123da7b22e15d5015d2b4bf1efb0296e7aa3162672e0257c
crc32: 3D6D90B3
md5: a68a851e1a79cf9806f6e96560071c73
sha1: a74cc85e07dcda7ea964b3bb07ef7eaedc418288
sha256: a36c23e7da65bd43123da7b22e15d5015d2b4bf1efb0296e7aa3162672e0257c
sha512: bc2b10e7a5c6d40837492166fcf897d9e7e08196439299104c678b032fbb96b37f9b52b94146c801a681e8fe3dd36feda8ba5823b8cf615f960075dc376dad46
ssdeep: 24576:xRRoFG97AQ3v4Rnqi5j2ComxWnFfuIRDvOcyI8See/CpglUI53XSs8GiF+U7pkZA:HQGZAtBqE3Wn4IB5+SCqGeQGiNOXybh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B095232B2EE0551AEA714838327AC2365C37BCB57028985270EC5F53BF3C9967D906F6
sha3_384: 2845a6a8cadce287f7b3887918998630b842a8f3c7a61958063d70e6a0bb73af66725fc66dc710a0b81cfdbe642eea9b
ep_bytes: eb05888ab03bf650eb05ddbf76c191e8
timestamp: 2074-02-27 05:37:54

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.aoqv also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47594020
FireEyeGeneric.mg.a68a851e1a79cf98
McAfeeArtemis!A68A851E1A79
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.20556
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058b8a21 )
AlibabaTrojanSpy:Win32/Stealer.e01f0ba4
K7GWTrojan ( 0058b8a21 )
Cybereasonmalicious.e07dcd
ArcabitTrojan.Generic.D2D63A24
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CV
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan-Spy.Win32.Stealer.aoqv
BitDefenderTrojan.GenericKD.47594020
RisingTrojan.Generic@ML.99 (RDMK:PziooBOBb+QQoVxLEKoHbQ)
Ad-AwareTrojan.GenericKD.47594020
EmsisoftTrojan.GenericKD.47594020 (B)
DrWebTrojan.PWS.Stealer.31832
TrendMicroTROJ_GEN.R049C0WLB21
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
Paloaltogeneric.ml
WebrootW32.Trojan.Gen
GridinsoftRansom.Win32.Occamy.vb
MicrosoftExploit:Win32/ShellCode!ml
ViRobotTrojan.Win32.Z.Occamy.1962704
GDataTrojan.GenericKD.47594020
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R456990
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.3rZ@ae@t2efk
ALYacTrojan.GenericKD.47594020
MAXmalware (ai score=80)
VBA32BScope.Trojan.Occamy
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R049C0WLB21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Spy.Win32.Stealer.aoqv?

Trojan-Spy.Win32.Stealer.aoqv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment