Spy Trojan

How to remove “Trojan-Spy.Win32.Stealer.apad”?

Malware Removal

The Trojan-Spy.Win32.Stealer.apad is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.apad virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.apad?


File Info:

name: 33DD045DABE17C573277.mlw
path: /opt/CAPEv2/storage/binaries/50a4ced4140a75dd92bc5ae840726aa33152582ee8cf389d0b4d8b9c8c8e206f
crc32: 93FB21E1
md5: 33dd045dabe17c573277ffbdc939ab4b
sha1: 21851125412b4d8ea7d6bc7400b305c9cbb80bbc
sha256: 50a4ced4140a75dd92bc5ae840726aa33152582ee8cf389d0b4d8b9c8c8e206f
sha512: cbb0882e13e0243ba5d111e4d70ce0741644eeac331ed3f2e678738e92e40be0c16ed2ed98a6ded2c459e85c0f5d27b8110716415af20f18a6fed4fc9430d4bc
ssdeep: 12288:OL3HCAO/exxvJa4eP6dliKpxCKxtP6Q1djBHyW3GvSF1CJPeLm6Rm:qHCB/e44eCldHPH1djB1GOIPe66R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T176259D42AFDC5458D4732A30A93AC57116133D79AD30D5AF30EB7E1FFAB1703996AA02
sha3_384: b867f2dddf44cb722d15d24e68d43de52576d37a01e97650594af8ba309bcb57b01032363235435b586f720b68dbf21e
ep_bytes: eb05d28c52ad3c50eb05c0a6be6bb2e8
timestamp: 2049-06-04 19:11:51

Version Info:

CompanyName: NVIDIA Corporation
FileDescription: NVIDIA Streamer Server Component
InternalName: nvstreamer
LegalCopyright: (C) 2017 NVIDIA Corporation. All rights reserved.
OriginalFilename: nvstreamer.exe
ProductName: NVIDIA Streamer
ProductVersion: gs_04_02 23124921
Translation: 0x0009 0x04b0

Trojan-Spy.Win32.Stealer.apad also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
CAT-QuickHealTrojanSpy.Stealer
ALYacTrojan.GenericKD.38225637
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.20566
SangforSpyware.Win32.Stealer.apad
K7AntiVirusTrojan ( 0058b97b1 )
AlibabaTrojanSpy:Win32/Stealer.10c593fc
K7GWTrojan ( 0058b97b1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CY
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.apad
BitDefenderTrojan.GenericKD.38225637
ViRobotTrojan.Win32.Z.Agent.1020592
MicroWorld-eScanTrojan.GenericKD.38225637
Ad-AwareTrojan.GenericKD.38225637
SophosMal/Generic-S
DrWebTrojan.PWS.Steam.23978
TrendMicroTROJ_GEN.R002C0PLB21
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.dh
FireEyeGeneric.mg.33dd045dabe17c57
EmsisoftTrojan.GenericKD.38225637 (B)
IkarusTrojan.Win32.Obsidium
GDataTrojan.GenericKD.38225637
WebrootW32.Trojan.Gen
AviraTR/Spy.Stealer.eakng
Antiy-AVLTrojan/Generic.ASMalwS.34F5308
KingsoftWin32.Heur.KVM007.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.ns
ArcabitTrojan.Generic.D24746E5
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R456217
Acronissuspicious
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=80)
VBA32BScope.Trojan.Tiggre
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0PLB21
RisingSpyware.Stealer!8.3090 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34114.!q3@aievDUei
AVGWin32:Trojan-gen
Cybereasonmalicious.5412b4
Paloaltogeneric.ml
MaxSecureTrojan.Malware.73763925.susgen

How to remove Trojan-Spy.Win32.Stealer.apad?

Trojan-Spy.Win32.Stealer.apad removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment