Spy Trojan

Trojan-Spy.Win32.Stealer.cspe information

Malware Removal

The Trojan-Spy.Win32.Stealer.cspe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.cspe virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Stealer.cspe?


File Info:

name: 243DF15FF3DEC4F7D2CB.mlw
path: /opt/CAPEv2/storage/binaries/0c7a8e3611c2d064307fe1f0b659bd0155caf32f348125ac6c01dc56e671f269
crc32: E5F13012
md5: 243df15ff3dec4f7d2cbcf0546c1af1e
sha1: 109d3595579e7523307fc083dcff32280c63d327
sha256: 0c7a8e3611c2d064307fe1f0b659bd0155caf32f348125ac6c01dc56e671f269
sha512: 5c589163f4675b216987ee4d8a9548c24ce35bc914afc25aba8d71e1227eeeb97d3664675251b12a420f8e54ee1a1ba764550126c2c92ac3f83110f177220034
ssdeep: 24576:8+x//uI1negYpYzhBF47JMyPdbXh1aelpqR5jFDlk6OLBa599l3RuQ553138:///uI1nwZaFDlk6OFaD9l3a
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13EC52B135A8B0D75DDD23BB4A1CB633EA734ED30CA3A9B7BB608C43959532C56C1A742
sha3_384: 9b0de39e834ef381f7d627eae2dabbfee7dc18b78170d0c1292437176df2f4ee9d3745f31a5b9329b557b1ad3e87a005
ep_bytes: 83ec0cc705b8e3530000000000e87ef8
timestamp: 2022-10-01 07:09:28

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.cspe also known as:

DrWebTrojan.PWS.StealerNET.125
MicroWorld-eScanTrojan.GenericKDZ.92517
FireEyeTrojan.GenericKDZ.92517
McAfeeGenericRXAA-AA!243DF15FF3DE
CylanceUnsafe
SangforTrojan.Win32.Kryptik.HQZO
BitDefenderThetaGen:NN.ZexaF.34698.K!Z@aa6@ite
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQZO
APEXMalicious
ClamAVWin.Trojan.Redlinestealer-9972824-0
KasperskyTrojan-Spy.Win32.Stealer.cspe
BitDefenderTrojan.GenericKDZ.92517
NANO-AntivirusTrojan.Win32.Stealer.jsujyt
AvastWin32:Evo-gen [Trj]
Ad-AwareTrojan.GenericKDZ.92517
SophosTroj/Steal-CYZ
F-SecureTrojan.TR/Crypt.Agent.ewmuy
VIPRETrojan.GenericKDZ.92517
McAfee-GW-EditionBehavesLike.Win32.BadFile.vh
EmsisoftTrojan-Spy.Stealer (A)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.14K7H74
GoogleDetected
AviraTR/Crypt.Agent.ewmuy
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Generic.D16965
ZoneAlarmTrojan-Spy.Win32.Stealer.cspe
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.US.R523930
VBA32BScope.Malware-Cryptor.MTA
ALYacTrojan.GenericKDZ.92517
MalwarebytesMalware.AI.731130628
RisingBackdoor.Agent!8.C5D (TFE:5:roJ2h4dAxDP)
IkarusTrojan.Win32.RedlineStealer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HQDK!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Spy.Win32.Stealer.cspe?

Trojan-Spy.Win32.Stealer.cspe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment