Spy Trojan

Trojan-Spy.Win32.Stealer.axgy malicious file

Malware Removal

The Trojan-Spy.Win32.Stealer.axgy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.axgy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Arabic (Algeria)
  • Unconventionial language used in binary resources: Serbian (Latin)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.axgy?


File Info:

name: 52DBD0A9182A57F35F22.mlw
path: /opt/CAPEv2/storage/binaries/a804c63aba545f44e97974c085236e35d3f16187267e461cf52e0b5392388816
crc32: A74B3D13
md5: 52dbd0a9182a57f35f227cfa085590ba
sha1: a9eb51f3298544240f8f688088be481d9adfe4b3
sha256: a804c63aba545f44e97974c085236e35d3f16187267e461cf52e0b5392388816
sha512: 8961cae8d1087712d9e1f3cd81bec1efde21e6b65330168d92731143f0e8e1e15530bc57560d748e46a95cd83ad053d2ea1c3275e692c75b9ece95e0115df368
ssdeep: 12288:3ZR0xtPo5D2pljF3O2m+fu26SfZ9o5TGL6EuBr1EWl/cMDsf3:3ZCxtw5CpljcGVlxC5bl/M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ECF4F18277E41369EC737A7259BF0B3296A0B8E26535CB6F654313769FE21018C17723
sha3_384: be7791a711059ca6670623731b31877b295aa62d92f79d98fe4082f5299da6bd5331aa09e7e4245b9aca8e7f5aa05bf9
ep_bytes: eb0581c204441650eb058686f44cc4e8
timestamp: 2049-10-06 18:19:01

Version Info:

CompanyName: Realtek Semiconductor
FileDescription: Realtek HD audio menadžer
FileVersion: 1, 0, 0, 9
InternalName: EP.exe
LegalCopyright: 2017 (c) Realtek Semiconductor. All rights reserved.
OriginalFilename: EP.exe
ProductName: Realtek HD audio menadžer
ProductVersion: 1, 0, 0, 9
Translation: 0x0419 0x04e4

Trojan-Spy.Win32.Stealer.axgy also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.GenericKDZ.82112
FireEyeGeneric.mg.52dbd0a9182a57f3
McAfeeArtemis!52DBD0A9182A
MalwarebytesSpyware.RedLineStealer
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0058caae1 )
K7AntiVirusTrojan ( 0058caae1 )
BitDefenderThetaGen:NN.ZexaF.34114.Tq3@aKlu4a9P
CyrenW32/Trojan.BKSJ-5254
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.axgy
AlibabaTrojanSpy:Win32/Stealer.3ac36a32
Ad-AwareTrojan.GenericKDZ.82112
DrWebTrojan.PWS.Steam.24516
SophosMal/Generic-S
eGambitUnsafe.AI_Score_96%
AviraTR/Spy.Stealer.wzwcg
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D140C0
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacTrojan.GenericKDZ.82112
MAXmalware (ai score=85)
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen

How to remove Trojan-Spy.Win32.Stealer.axgy?

Trojan-Spy.Win32.Stealer.axgy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment