Spy Trojan

Trojan-Spy.Win32.Stealer.rpl information

Malware Removal

The Trojan-Spy.Win32.Stealer.rpl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.rpl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs

How to determine Trojan-Spy.Win32.Stealer.rpl?


File Info:

crc32: 4A7238EB
md5: a3fd7ddf348da60561e534f733571e1f
name: ebukanwa.exe
sha1: bfaf2cb7d37daed5a9d614c0e5377821a148e0a1
sha256: 6e2f2dc9a4a0f0be3b39ccc7c733a7a0ec3a0707c2269085ae05437832278297
sha512: 5ea645ff5ead9f8a93d52d7aeb9a6a8f64b8afaa166891f9ceff54a204a6bf56cf13cbdb50d296786550350077b25bf0f69005a681085e63ea2ba7bb2e87de3b
ssdeep: 49152:Cu0c++OCvkGs9FaQBG4PW+CO4tA3MlPkFa4tY:NB3vkJ9XGtO4i3Ml83
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Spy.Win32.Stealer.rpl also known as:

MicroWorld-eScanTrojan.GenericKD.33297578
FireEyeGeneric.mg.a3fd7ddf348da605
ALYacTrojan.GenericKD.33297578
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33297578
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7d37da
TrendMicroTROJ_GEN.R011C0PBL20
F-ProtW32/AutoIt.NS.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33297578
KasperskyTrojan-Spy.Win32.Stealer.rpl
AlibabaTrojan:Win32/autoit.ali2000008
NANO-AntivirusTrojan.Win32.Stealer.hbhziq
AegisLabTrojan.Win32.AutoIt.4!e
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Ad-AwareTrojan.GenericKD.33297578
EmsisoftTrojan.GenericKD.33297578 (B)
F-SecureTrojan.TR/AD.Hawkexe.knzgo
DrWebTrojan.Siggen8.58785
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
MaxSecureTrojan.Malware.74836404.susgen
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
CyrenW32/AutoIt.NS.gen!Eldorado
AviraTR/AD.Hawkexe.knzgo
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FC14AA
ZoneAlarmTrojan-Spy.Win32.Stealer.rpl
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Trojan/AU3.Wacatac.S1079
McAfeeArtemis!A3FD7DDF348D
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ZonerTrojan.Win32.87692
ESET-NOD32a variant of Win32/Injector.Autoit.FCH
TrendMicro-HouseCallTROJ_GEN.R011C0PBL20
TencentWin32.Trojan-spy.Stealer.Lohx
IkarusTrojan.Autoit
FortinetAutoIt/Injector.FCK!tr
AVGSNH:Script [Dropper]
AvastSNH:Script [Dropper]
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.Spy.c24

How to remove Trojan-Spy.Win32.Stealer.rpl?

Trojan-Spy.Win32.Stealer.rpl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment