Spy Trojan

Trojan-Spy.Win32.Stealer.rkm removal

Malware Removal

The Trojan-Spy.Win32.Stealer.rkm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.rkm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Spy.Win32.Stealer.rkm?


File Info:

crc32: B1BF527E
md5: b48d7a04374fcbd33ec8e12a467de319
name: azo.exe
sha1: 71ebfbb59545416eebba8202bc4f169fa7f21d87
sha256: 81b451d412d4dd03ff50113008a0d4072ddb407993027a87610bb78c8c41850c
sha512: 2c97352a9b71ad972c973d3daf34c5c805f586b13b07f2d0f3a0fdf3716c4215c0fe56f6e212f618b935bf91f741e5ca94e66d7b750bbb8cf830f7f307d49372
ssdeep: 24576:qAHnh+eWsN3skA4RV1Hom2KXSmdaAxVmePl0gCLLqLyF/Lo5:9h+ZkldoPKi2aAxcgKym/S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Spy.Win32.Stealer.rkm also known as:

MicroWorld-eScanTrojan.GenericKD.42572527
FireEyeGeneric.mg.b48d7a04374fcbd3
CAT-QuickHealTrojan.Wacatac
Qihoo-360Win32/Trojan.Spy.54c
McAfeeArtemis!B48D7A04374F
CylanceUnsafe
AegisLabTrojan.Win32.Nymeria.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42572527
K7GWRiskware ( 0040eff71 )
TrendMicroTrojan.Win32.WACATAC.THBABBO
F-ProtW32/Autoit.G.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Autoit-7585910-0
GDataTrojan.GenericKD.42572527
KasperskyTrojan-Spy.Win32.Stealer.rkm
AlibabaTrojanSpy:Win32/Stealer.a55eaa90
NANO-AntivirusTrojan.Win32.AutoIt.hasrrq
AvastScript:SNH-gen [Trj]
TencentWin32.Trojan-spy.Stealer.Pezl
Ad-AwareTrojan.GenericKD.42572527
EmsisoftTrojan.GenericKD.42572527 (B)
F-SecureTrojan.TR/Autoit.rcdoo
DrWebTrojan.AutoIt.727
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
CyrenW32/Autoit.G.gen!Eldorado
AviraTR/Autoit.rcdoo
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2899AEF
ZoneAlarmTrojan-Spy.Win32.Stealer.rkm
MicrosoftTrojan:Win32/Predator.BC!MTB
AhnLab-V3Trojan/AU3.Wacatac.S1079
ALYacSpyware.AgentTesla
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack.AutoIt
ESET-NOD32a variant of Win32/Injector.Autoit.FBV
TrendMicro-HouseCallTrojan.Win32.WACATAC.THBABBO
RisingTrojan.Obfus/Autoit!1.C075 (CLASSIC)
YandexTrojan.AvsArher.bS970C
IkarusTrojan-Spy.Keylogger.AgentTesla
eGambitUnsafe.AI_Score_98%
FortinetAutoIt/Injector.EZY!tr
AVGScript:SNH-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Spy.Win32.Stealer.rkm?

Trojan-Spy.Win32.Stealer.rkm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment