Spy Trojan

Trojan-Spy.Win32.Stealer.oq removal instruction

Malware Removal

The Trojan-Spy.Win32.Stealer.oq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.oq virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Spanish
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system

How to determine Trojan-Spy.Win32.Stealer.oq?


File Info:

crc32: C54F5FD7
md5: 56714462adc6e043a302e05716c9909d
name: 56714462ADC6E043A302E05716C9909D.mlw
sha1: b996e8229d0a8d8aa779fa776b8a02382b34725d
sha256: a242dc6908a47e5f8494f484920a3245a97893102487a0021abba86944a70af7
sha512: aa1964ca8235f1005dee6c462eaae514c89cdf6849a7c4a8e1c16384542eca6898fddc50b31fb905497476b28f31ec3c2f16ce33c09f1a51fd6e49552d965b59
ssdeep: 6144:3w53LhiGB9n1bC1f0CDpoiO2iM6d6Aqz0AeV8/6q:A53LhisNF2fLTT6d6cL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 4.6.2
Translation: 0x0809 0x04b0

Trojan-Spy.Win32.Stealer.oq also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d2981 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
ALYacTrojan.Mint.Jamg.C
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.590
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Stealer.02e60c42
K7GWTrojan ( 0053d2981 )
Cybereasonmalicious.2adc6e
CyrenW32/Midie.N.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GLAE
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Ransomware.Gandcrab5-6697262-1
KasperskyTrojan-Spy.Win32.Stealer.oq
BitDefenderTrojan.Mint.Jamg.C
NANO-AntivirusTrojan.Win32.GandCrypt.fihmdn
ViRobotTrojan.Win32.GandCrab.251904
MicroWorld-eScanTrojan.Mint.Jamg.C
TencentWin32.Trojan-spy.Stealer.Svrd
Ad-AwareTrojan.Mint.Jamg.C
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Vigorf.GL@7vgi1m
BitDefenderThetaGen:NN.ZexaF.34692.su0@aWO4O8G
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.56714462adc6e043
EmsisoftTrojan.Mint.Jamg.C (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Stealer.ct
AviraHEUR/AGEN.1102747
Antiy-AVLTrojan/Generic.ASMalwS.2836A88
MicrosoftVirTool:Win32/CeeInject.QX!bit
AegisLabTrojan.Win32.Stealer.4!c
GDataTrojan.Mint.Jamg.C
AhnLab-V3Trojan/Win32.Gandcrab.R237847
Acronissuspicious
McAfeeTrojan-FQDU!56714462ADC6
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GenAsa!Nn6haA8mB1g
IkarusTrojan.Crypt
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.GLOO!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Spy.Win32.Stealer.oq?

Trojan-Spy.Win32.Stealer.oq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment