Spy Trojan

About “Trojan-Spy.Win32.Stealer.ecmk” infection

Malware Removal

The Trojan-Spy.Win32.Stealer.ecmk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.ecmk virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Stealer.ecmk?


File Info:

name: CE0EB519B037816A73BF.mlw
path: /opt/CAPEv2/storage/binaries/f34735e31dcb18528fac64a142b64aa09dbc07a4ac9e28c514168349be57c96b
crc32: DD1AA70F
md5: ce0eb519b037816a73bfbdb4a9e5617b
sha1: 88cfdcf69d5c2dd8c5f9573f05ef9d3019074fb6
sha256: f34735e31dcb18528fac64a142b64aa09dbc07a4ac9e28c514168349be57c96b
sha512: 6ef0247963d5ec4b47d1f4130bffb00769e590ecabad02b734dbf419f822b4f2591d017737651b8c72bd9d631e3a5624d5018822b0d19e5b205f730832229285
ssdeep: 24576:Y0Rx7fIuM1IEqsfDp584Symem52e3dsRjHx4K:JbLM1LqsrE5226jHCK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12415128178C0B130DD714532695EB953ACBCF8A19E70DD9F3B50234E8A756E1BAB022E
sha3_384: 7e31ec67cc81768f28138edec3c901580f9220301ff8dfb895ed9f02ad73c10d059ca00078d0b6b0a660b976020a85ef
ep_bytes: e8e2020000e974feffff558bec83ec0c
timestamp: 2023-06-19 16:25:12

Version Info:

Comments: This is a legitimate application.
CompanyName: JSC Partnership Fund
FileDescription: JSC Partnership Fund Product
FileVersion: 450
InternalName: N4LGxsZwcmny
LegalCopyright: © JSC Partnership Fund All rights reserved.
LegalTrademarks: © JSC Partnership Fund Trademarks
OriginalFilename: aPysGMFC.exe
ProductName: kkDwki1QHr
ProductVersion: 450
Translation: 0x0407 0x04b0

Trojan-Spy.Win32.Stealer.ecmk also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanTrojan.GenericKD.67628738
FireEyeGeneric.mg.ce0eb519b037816a
ALYacTrojan.GenericKD.67628738
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent.Win32.3564203
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a6ca51 )
AlibabaTrojanSpy:Win32/Stealer.7bf8f0ec
K7GWTrojan ( 005a6ca51 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D407EEC2
BitDefenderThetaGen:NN.ZexaF.36318.4u0@ae3yoUki
VirITTrojan.Win32.Genus.RLT
CyrenW32/Kryptik.KAR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTTW
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.ecmk
BitDefenderTrojan.GenericKD.67628738
NANO-AntivirusTrojan.Win32.Stealer.jxdnzg
AvastWin32:BotX-gen [Trj]
RisingTrojan.RedLine!8.120FD (TFE:1:NGWb0uJrpeI)
EmsisoftTrojan.GenericKD.67628738 (B)
F-SecureTrojan.TR/Crypt.Agent.oqzcp
DrWebTrojan.Packed2.45386
VIPRETrojan.GenericKD.67628738
TrendMicroTrojan.Win32.PRIVATELOADER.YXDFTZ
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ZR
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.oqzcp
Antiy-AVLTrojan/Win32.Kryptik
XcitiumMalware@#2jpfc230jopxl
MicrosoftTrojan:Win32/Amadey.ADY!MTB
ViRobotTrojan.Win.Z.Kryptik.928768.B
ZoneAlarmTrojan-Spy.Win32.Stealer.ecmk
GDataTrojan.GenericKD.67628738
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R587845
McAfeeGenericRXWF-GF!CE0EB519B037
MAXmalware (ai score=82)
VBA32BScope.TrojanPSW.RedLine
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXDFTZ
TencentMalware.Win32.Gencirc.13d9010a
IkarusTrojan.Win32.Redline
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HTTW!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.9b0378
DeepInstinctMALICIOUS

How to remove Trojan-Spy.Win32.Stealer.ecmk?

Trojan-Spy.Win32.Stealer.ecmk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment