Spy Trojan

Trojan-Spy.Win32.Stealer.ccrz malicious file

Malware Removal

The Trojan-Spy.Win32.Stealer.ccrz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.ccrz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Stealer.ccrz?


File Info:

name: F97AA35256927C691FB0.mlw
path: /opt/CAPEv2/storage/binaries/5580724bc2d4cc6e095dde65577be66f97572baeba7bd4a7dfc84a140428d0de
crc32: 1D5C75CE
md5: f97aa35256927c691fb02190cdc2f14c
sha1: 941574f68d074a1dbe9c5153259a4534f285e350
sha256: 5580724bc2d4cc6e095dde65577be66f97572baeba7bd4a7dfc84a140428d0de
sha512: 4b195f8681e23cf3d9ab94f62841c0a57a485de790b1b63c8c4b84aa1fc5e8501dfcd0dc1d5e1f3631bc582fdeef68038e506c78d12d676312a53e5facb044e4
ssdeep: 12288:ULvxqQSN01YWGZQ1WKRUj8eUXuS6iiuuuKIaCbf82xR0+OWBWp+cuScQuZpfqng3:Uxc81LRleUeSyAbf82ovyWUMkWoyYX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T126656C20B791911CFCF316FA9AFE206C992DBAF00B28A0C751C42ADD5A65EF57C31653
sha3_384: b2826a4b072dc041fa28318ebbd2c969855c47fdd03638a6d405a8c989fc8d65d6dc6d6d45c5c6ae64d56618ae4f7c5c
ep_bytes: e9d39c0500e94e370800e9f8131000e9
timestamp: 2022-06-22 12:09:16

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.ccrz also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
MicroWorld-eScanGen:Variant.Lazy.199606
FireEyeGen:Variant.Lazy.199606
ALYacGen:Variant.Lazy.199606
SangforSpyware.Win32.Stealer.gen
K7AntiVirusTrojan ( 00594ad91 )
K7GWTrojan ( 00594ad91 )
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HPXQ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.ccrz
BitDefenderGen:Variant.Lazy.199606
AvastWin32:SpywareX-gen [Trj]
Ad-AwareGen:Variant.Lazy.199606
SophosMal/Generic-S
DrWebTrojan.PWS.Stealer.32450
TrendMicroTrojanSpy.Win32.REDLINE.YXCFWZ
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Lazy.199606 (B)
GDataGen:Variant.Lazy.199606
AviraTR/AD.Nekark.fvudq
ArcabitTrojan.Lazy.D30BB6
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R500213
McAfeeGenericRXTK-EE!F97AA3525692
MAXmalware (ai score=84)
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCFWZ
RisingStealer.Agent!8.C2 (CLOUD)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/PossibleThreat
AVGWin32:SpywareX-gen [Trj]

How to remove Trojan-Spy.Win32.Stealer.ccrz?

Trojan-Spy.Win32.Stealer.ccrz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment