Spy Trojan

Trojan-Spy.Win32.Stealer.kl information

Malware Removal

The Trojan-Spy.Win32.Stealer.kl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.kl virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.kl?


File Info:

crc32: 6F0B2144
md5: fe5a037e0ac35baa150234dfcaa22cad
name: FE5A037E0AC35BAA150234DFCAA22CAD.mlw
sha1: 73f9e608a05ab9fec94def2ef463b8d1d3ec64ce
sha256: b7a2b41a8b8bd9ba9feeec81eb6880898994a562967fe1dda31269c9d9108f12
sha512: 0caa6ef4354a87bd668870e52158e2f9d8be6c12b8f4f1fd4ed29601b414c5ccc251ddf892388bf0dfea1028b700213108aa30add84b9c2d1ea7b45f7c54f552
ssdeep: 3072:maIaOSCmTOnZ25j23J6HDQ3KpeLaJLZSMLpX8/kPkDU8nmCZIL/:maIaOSCaO45jU6j10KtScXxko8mCZE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.kl also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053cd3e1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24403
CynetMalicious (score: 100)
ALYacTrojan.Brsecmon.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Stealer.12e1f559
K7GWTrojan ( 0053cd3e1 )
Cybereasonmalicious.e0ac35
CyrenW32/Kryptik.KY.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKYN
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.Win32.Stealer.kl
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Stealer.fiaqal
MicroWorld-eScanTrojan.Brsecmon.1
TencentMalware.Win32.Gencirc.10cc61e4
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/Kryptik-CQ
ComodoTrojWare.Win32.NeutrinoPOS.OA@848f5a
BitDefenderThetaGen:NN.ZexaF.34790.kuW@aS1hHGiO
TrendMicroTrojanSpy.Win32.CLIPBANKER.SMB
McAfee-GW-EditionBehavesLike.Win32.Backdoor.ch
FireEyeGeneric.mg.fe5a037e0ac35baa
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Azorult.j
AviraHEUR/AGEN.1121554
eGambitUnsafe.AI_Score_79%
Antiy-AVLTrojan/Generic.ASMalwS.281AEBB
MicrosoftTrojan:Win32/Gandcrab.AF
ZoneAlarmTrojan-Spy.Win32.Stealer.kl
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.Gandcrab.R237774
Acronissuspicious
McAfeeTrojan-FPYT!FE5A037E0AC3
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMB
RisingTrojan.Kryptik!1.B426 (CLASSIC)
YandexTrojan.GenAsa!Qf7QyAmM+14
IkarusTrojan.Crypt
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Spy.Win32.Stealer.kl?

Trojan-Spy.Win32.Stealer.kl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment