Spy Trojan

Trojan-Spy.Win32.Stealer.cfxc information

Malware Removal

The Trojan-Spy.Win32.Stealer.cfxc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.cfxc virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.cfxc?


File Info:

name: D9B9B5124E23A2469AD4.mlw
path: /opt/CAPEv2/storage/binaries/d05c729d5d0682f57b0156fdd8c609629ac766007229a54e2288786abb3cc2b7
crc32: 28ADCC9C
md5: d9b9b5124e23a2469ad44b233cfc4dde
sha1: 8aec00624c20d32c0793894018493f05f5fbcc44
sha256: d05c729d5d0682f57b0156fdd8c609629ac766007229a54e2288786abb3cc2b7
sha512: 8c45cdf398a91e9d995be4f459714a33ab405456697af3ac0837e4d08715ce005bfef4bd946dcccc7a782c8f2ec291462a7d8aea81ecc98cf516920c86a57903
ssdeep: 24576:hbUu7kd8+NFiKXQSvYnYMjLoXCnMxgdaN/qNbeXjPsfPoTHBLiqdYlqlaVFl3Ruo:yvXQDMQEsnoTHBP0l35
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T119C52B139A8B0E75DDD23BB461CB633AA734ED30CA3A9B7FB608C53559532C46C1A742
sha3_384: f0a7c67531ab7d389e8ac4a8be67b3b1e6a918ea84e66cc567597f1020b0bbdb1f92f3986f146bafc1f157008b956a0b
ep_bytes: 83ec0cc705b813520000000000e81ee1
timestamp: 2022-07-16 18:08:06

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.cfxc also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.89833
FireEyeTrojan.GenericKDZ.89833
ALYacTrojan.GenericKDZ.89833
CylanceUnsafe
VIPRETrojan.GenericKDZ.89833
K7AntiVirusTrojan ( 0059579c1 )
K7GWTrojan ( 0059579c1 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQDK
ClamAVWin.Packed.Trojanx-9956396-0
KasperskyTrojan-Spy.Win32.Stealer.cfxc
BitDefenderTrojan.GenericKDZ.89833
NANO-AntivirusTrojan.Win32.Inject4.jqeira
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKDZ.89833
DrWebTrojan.Inject4.37966
EmsisoftTrojan.GenericKDZ.89833 (B)
GDataWin32.Trojan.PSE.1PMRMI2
AviraTR/Crypt.Agent.ujnqy
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D15EE9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLineStealer.R504948
McAfeeGenericRXTQ-NO!D9B9B5124E23
VBA32BScope.TrojanPSW.RedLine
MalwarebytesMalware.AI.4194616257
RisingStealer.Agent!8.C2 (TFE:dGZlOgXFuE80t3MBkg)
IkarusTrojan.Win32.Krypt
MaxSecureSpy.W32.Convagent.gen_232116
FortinetW32/RedLineStealer.B!tr
AVGWin32:Trojan-gen

How to remove Trojan-Spy.Win32.Stealer.cfxc?

Trojan-Spy.Win32.Stealer.cfxc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment