Spy Trojan

Trojan-Spy.Win32.Stealer.apsb removal

Malware Removal

The Trojan-Spy.Win32.Stealer.apsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.apsb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.apsb?


File Info:

name: EA9B78A8E7D31246A4D6.mlw
path: /opt/CAPEv2/storage/binaries/80e48666b127561b08209f791a60ceedef6dce8f27b0136b498ea99d66f52835
crc32: AEA8F519
md5: ea9b78a8e7d31246a4d60a8b59967a42
sha1: 35df1c36baa40bd1746605c3eb57d24ea09b3162
sha256: 80e48666b127561b08209f791a60ceedef6dce8f27b0136b498ea99d66f52835
sha512: cd9e8c7c49399ca9eab55ba570ef2369405ffa0455e22e31cd5b01e51605a9387e29f037ce18c835dd3e925d408bfed2228134434163abe8c9b978b0b4ac38ef
ssdeep: 24576:jxusebVjI6HzTHm8xMMxmng6G8UMeq5cH:du9VjzTpOng3e6H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F745387720217089D59AD8F1DF7FE43222AB3F9DAC94F5389852361D4662250703EBFA
sha3_384: 7a6bb4b664e32dfafcef1eeb491f8c5e15bc5368bd2ff32474b14d6167f7a1a171984cd676c6092d9d2c1599516b756f
ep_bytes: eb05263b1da4be50eb05f0b8d6099be8
timestamp: 2041-12-10 14:28:31

Version Info:

CompanyName: Piriform Software Ltd
FileDescription: CCleaner Installer
FileVersion: 5.87.0.9306
LegalCopyright: Copyright © 2005-2021 Piriform Software Ltd
ProductName: CCleaner
Translation: 0x0000 0x04b0

Trojan-Spy.Win32.Stealer.apsb also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Siggen16.4161
MicroWorld-eScanTrojan.GenericKD.38250774
FireEyeGeneric.mg.ea9b78a8e7d31246
McAfeeArtemis!EA9B78A8E7D3
CylanceUnsafe
K7AntiVirusTrojan ( 0058b9741 )
AlibabaTrojanSpy:Win32/Stealer.cb21798b
K7GWTrojan ( 0058b9741 )
Cybereasonmalicious.6baa40
ArcabitTrojan.Generic.D247A916
BitDefenderThetaGen:NN.ZexaF.34084.ir3@aOBd5Lki
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CW
TrendMicro-HouseCallTROJ_GEN.R002C0WLE21
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.apsb
BitDefenderTrojan.GenericKD.38250774
NANO-AntivirusTrojan.Win32.Stealer.jjcvup
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.38250774
EmsisoftTrojan.GenericKD.38250774 (B)
TrendMicroTROJ_GEN.R002C0WLE21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
JiangminTrojanSpy.Stealer.kih
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Stealer.ap.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftExploit:Win32/ShellCode!ml
GDataWin32.Trojan-Stealer.CredStealer.MGGI6B
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Exploit.Shellcode
ALYacTrojan.GenericKD.38250774
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack
APEXMalicious
RisingTrojan.Generic@ML.99 (RDMK:/TN1F/jxUaCv8LdhBUb/1w)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Spy.Win32.Stealer.apsb?

Trojan-Spy.Win32.Stealer.apsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment