Spy Trojan

Trojan-Spy.Win32.Stealer.cllh removal guide

Malware Removal

The Trojan-Spy.Win32.Stealer.cllh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.cllh virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan-Spy.Win32.Stealer.cllh?


File Info:

name: 82AB855D2D249464B0E6.mlw
path: /opt/CAPEv2/storage/binaries/ebf9b0cc42300ce226280c1cfe3f8b7dd1a9a5f2f409fec1fabead70b2cca41b
crc32: CCC2AC1E
md5: 82ab855d2d249464b0e6dea7aa734c27
sha1: cb3c2d3c3324f8569c32bb62bd440660c4717d89
sha256: ebf9b0cc42300ce226280c1cfe3f8b7dd1a9a5f2f409fec1fabead70b2cca41b
sha512: 08becf63373aa054a8101afe92f8fd451df48826f73f6a9d5ef41729d7f44a82eb918166a4096bd8c9e11ad59890ac80094dd14cb1567d111241cd89d95f66fa
ssdeep: 24576:qnKCiAZQYhYg5OMMcMgvf5JlltTen7tRFdfSMsVFR3hWzN0jLEPN5irl3RuQ553r:DJA5KngLxhWzN0jY7irl3f
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T171C51A039A8B0E75DDC23BB461CB633AA734FD30CA3A9B7BF609C53559532D4681A742
sha3_384: 4f40bb600c9d37e6a4d9e45c15e1d736bc4ada7e3a6e23b3d1fd629cb007af7e61685b31e9677dab2b4b97887cfc3169
ep_bytes: 83ec0cc705b8e3510000000000e8deb6
timestamp: 2022-08-24 23:19:09

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.cllh also known as:

LionicTrojan.Win32.Stealer.12!c
MicroWorld-eScanTrojan.GenericKD.61493116
FireEyeTrojan.GenericKD.61493116
ALYacTrojan.GenericKD.61493116
CylanceUnsafe
SangforSpyware.Win32.Agent.Vuwb
K7AntiVirusTrojan ( 00595a1c1 )
BitDefenderTrojan.GenericKD.61493116
K7GWTrojan ( 00595a1c1 )
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQDK
CynetMalicious (score: 100)
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.cllh
AlibabaTrojanSpy:Win32/Stealer.62d71611
RisingSpyware.Convagent!8.12330 (TFE:5:vyWeQ8A22bD)
Ad-AwareTrojan.GenericKD.61493116
SophosMal/Generic-S
DrWebTrojan.PWS.Stealer.32450
VIPRETrojan.GenericKD.61493116
TrendMicroTrojanSpy.Win32.REDLINE.YXCHYZ
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.61493116 (B)
IkarusTrojan.Win32.Krypt
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.50E8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1KEPK3Q
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R512474
McAfeeArtemis!82AB855D2D24
VBA32Trojan.MSIL.InfoStealer.gen.U
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCHYZ
MaxSecureTrojan.Malware.121218.susgen
BitDefenderThetaGen:NN.ZexaF.34606.B!Z@aW1c5Fi
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]

How to remove Trojan-Spy.Win32.Stealer.cllh?

Trojan-Spy.Win32.Stealer.cllh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment