Spy Trojan

How to remove “Trojan-Spy.Win32.Stealer.etrc”?

Malware Removal

The Trojan-Spy.Win32.Stealer.etrc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.etrc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Spy.Win32.Stealer.etrc?


File Info:

name: 2B89D29EDC66C87A500F.mlw
path: /opt/CAPEv2/storage/binaries/1f913c17086ff7e2e9fdb6f27c7e451e5d832ca547cbf3959ac9972b54ec198b
crc32: C4D6EBED
md5: 2b89d29edc66c87a500f8f1d55831d78
sha1: 4a2b6046eb42b65b9466f6c869ae7c7538e0a1be
sha256: 1f913c17086ff7e2e9fdb6f27c7e451e5d832ca547cbf3959ac9972b54ec198b
sha512: 0aa2a17607bde0bef3cc093ed493f098c0e98b46062a04ae04e82fd79f3825522a5f56113ced9d013c57a4fc59b6366b76d494d857a062d97068ec328cc448b7
ssdeep: 98304:c69EwaUfyz8GfdpGmc72lGmPvV0rLbe8DJJdTW/AL2WDWz2XGTRu:c69EFhZfXGmIwBPvV0THDJJd6xWDi2X7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13956339B07CB0C00E05AD4B2919EF53B9E296E4A9CB0536F45F4AC27B4FC79C29997C1
sha3_384: d87ee1df1601f47aaa09668f232abccdca50537171d9992da0e0189d699c2f2ae7b10fd265830fc3b4cd3d424dbc769c
ep_bytes: eb08000805000000000060e800000000
timestamp: 2102-05-24 09:35:14

Version Info:

Comments:
CompanyName: MS
FileDescription: MsIo for Universal Holtek
FileVersion: 1.0
InternalName: MsIo
LegalCopyright: Copyright © 1998-2018, MS
LegalTrademarks:
OriginalFilename: MsIo.dll
PrivateBuild:
ProductName: MsIo
ProductVersion: 1.0
SpecialBuild:
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Stealer.etrc also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.69136385
ALYacTrojan.GenericKD.69136385
MalwarebytesMalware.Heuristic.1003
ZillyaTrojan.Stealer.Win32.145984
SangforTrojan.Win32.Agent.Vynu
K7AntiVirusTrojan ( 0058c50b1 )
AlibabaTrojanSpy:Win32/Stealer.729e1898
K7GWTrojan ( 0058c50b1 )
ArcabitTrojan.Generic.D41EF001
BitDefenderThetaGen:NN.ZexaF.36738.@B3@ae3RZRdi
CyrenW32/ABRisk.BSAA-8825
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Packed.Enigma.CE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.etrc
BitDefenderTrojan.GenericKD.69136385
AvastWin32:Evo-gen [Trj]
RisingStealer.Agent!8.C2 (CLOUD)
EmsisoftTrojan.GenericKD.69136385 (B)
F-SecureTrojan.TR/Spy.Stealer.lrzmy
VIPRETrojan.GenericKD.69136385
TrendMicroTrojanSpy.Win32.REDLINE.YXDIEZ
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.2b89d29edc66c87a
SophosMal/Generic-S
IkarusTrojan.Win64.Enigma
AviraTR/Spy.Stealer.lrzmy
Antiy-AVLTrojan[Spy]/Win32.Stealer
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Spy.Win32.Stealer.etrc
GDataTrojan.GenericKD.69136385
GoogleDetected
McAfeeArtemis!2B89D29EDC66
MAXmalware (ai score=85)
VBA32Trojan.Quasar
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDIEZ
TencentMalware.Win32.Gencirc.13ee2fcb
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.218125063.susgen
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Spy.Win32.Stealer.etrc?

Trojan-Spy.Win32.Stealer.etrc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment