Spy Trojan

Trojan-Spy.Win32.Stealer.cmrg removal tips

Malware Removal

The Trojan-Spy.Win32.Stealer.cmrg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.cmrg virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan-Spy.Win32.Stealer.cmrg?


File Info:

name: FCD53A5DD4DFAF9FCDF7.mlw
path: /opt/CAPEv2/storage/binaries/1e3f6d6062985a33984a199b865279cb557ab230292ca66fa07ec97b65450930
crc32: EADF2D6F
md5: fcd53a5dd4dfaf9fcdf7398769713ea1
sha1: f63c5567ac92c6c5f84c415f3d5dadf74c69ce27
sha256: 1e3f6d6062985a33984a199b865279cb557ab230292ca66fa07ec97b65450930
sha512: 12796efb1413d912c4f09de2ca4e6f80fc14d041007a42448ee353189e08befafc519d5eaa605b8048aa28dea1bb4c74a63b9fca93363958a00fc0685f7188c5
ssdeep: 24576:kW3hYmYZUPyoyMUtoXDrstX98NTheijKCJQY8RVBO4IXLMZ60l3RuQ55313l:kW++ljXaY8RVBO4IX6l3n
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T155C5F8036ACB1E75DDC23BB4618B533FA734EE30CA2A9B7BB608C53559532D46C1A742
sha3_384: 2dd809348584d2b385c5998db86cfb5aa79a8b35fed7887103a02050454900c6e4ddac0985edff704e499ff1c24261ad
ep_bytes: 83ec0cc705b863510000000000e84e87
timestamp: 2022-08-31 05:53:21

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.cmrg also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Bandra.7!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.136511
FireEyeGen:Variant.Fragtor.136511
McAfeeGenericRXUA-ZS!FCD53A5DD4DF
CylanceUnsafe
VIPREGen:Variant.Fragtor.136511
SangforTrojan.Win32.Agent.Vqra
K7GWTrojan ( 005979091 )
K7AntiVirusTrojan ( 005979091 )
ArcabitTrojan.Fragtor.D2153F
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQPJ
Paloaltogeneric.ml
ClamAVWin.Malware.Fragtor-9934292-0
KasperskyTrojan-Spy.Win32.Stealer.cmrg
BitDefenderGen:Variant.Fragtor.136511
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Fragtor.136511
EmsisoftGen:Variant.Fragtor.136511 (B)
DrWebTrojan.PWS.Steam.28157
TrendMicroTrojanSpy.Win32.REDLINE.YXCH5Z
McAfee-GW-EditionBehavesLike.Win32.Trojan.vh
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraTR/Crypt.Agent.haaeb
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.69757
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R513102
BitDefenderThetaGen:NN.ZexaF.34606.z!Z@a8qth7c
ALYacGen:Variant.Fragtor.136511
VBA32Trojan.MSIL.InfoStealer.gen.U
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCH5Z
RisingTrojan.Kryptik!8.8 (TFE:5:qFgFsCC2vGK)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Trojan-gen
Cybereasonmalicious.7ac92c
PandaTrj/Chgt.AD

How to remove Trojan-Spy.Win32.Stealer.cmrg?

Trojan-Spy.Win32.Stealer.cmrg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment