Spy Trojan

How to remove “Trojan-Spy.Win32.Stealer.rti”?

Malware Removal

The Trojan-Spy.Win32.Stealer.rti is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.rti virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Checks for the presence of known windows from debuggers and forensic tools
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
raw.githubusercontent.com
u6218636a7.ha004.t.justns.ru

How to determine Trojan-Spy.Win32.Stealer.rti?


File Info:

crc32: 09E29ECF
md5: d72bb98e5328baefd9ee894ff57ebeea
name: ___60_3.exe
sha1: 053d3536f97a354ca3488dff62d481c8863c4405
sha256: e038b7d3ffa0269d676e2103e032c3225c3206a83187d61dc7ef8e0784866bbc
sha512: 6db047c729e14bbe773bebdd3b02deecc36e85add1884f18edd7423d5d14c133f0725ae378e3369014d14db73508d9c8968c407366ea661cdc53bb1bfb827781
ssdeep: 6144:BCiPqQ8HLHKoFU3vf8PvHT5kfe8NhYFrgXejcukKW5E6FYST8iCI:FWHrKoaMnHT5kf7UFJjcukKWO6FFCI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: userbuild.exe
FileVersion: 2.2.2.2
CompanyName: CLR Company
ProductName: CLR
ProductVersion: 2.2.2.2
FileDescription: CLR Company
OriginalFilename: userbuild.exe
Translation: 0x0419 0x04b0

Trojan-Spy.Win32.Stealer.rti also known as:

DrWebTrojan.PWS.Steam.17786
MicroWorld-eScanGen:Variant.Ulise.99789
FireEyeGen:Variant.Ulise.99789
McAfeeGenericRXAA-AA!D72BB98E5328
CylanceUnsafe
K7AntiVirusSpyware ( 00560c701 )
BitDefenderGen:Variant.Ulise.99789
K7GWSpyware ( 00560c701 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.34090.ru1@aCm8m8jk
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Ulise.99789
KasperskyTrojan-Spy.Win32.Stealer.rti
AlibabaTrojanSpy:Win32/Generic.6d6e1dc2
AegisLabTrojan.Multi.Generic.4!c
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.ttgjk
McAfee-GW-EditionArtemis
Trapminemalicious.moderate.ml.score
EmsisoftTrojan-Spy.Agent (A)
IkarusTrojan-Spy.Agent
JiangminTrojanSpy.Stealer.cky
AviraTR/Spy.Agent.ttgjk
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Ulise.D185CD
ZoneAlarmTrojan-Spy.Win32.Stealer.rti
ALYacGen:Variant.Ulise.99789
MalwarebytesTrojan.Downloader
ESET-NOD32a variant of Win32/Spy.Agent.PWV
TrendMicro-HouseCallTROJ_GEN.R002H09BR20
RisingSpyware.Stealer!8.3090 (CLOUD)
eGambitPE.Heur.InvalidSig
FortinetW32/Agent.PWV!tr.spy
Ad-AwareGen:Variant.Ulise.99789
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Generic/Trojan.617

How to remove Trojan-Spy.Win32.Stealer.rti?

Trojan-Spy.Win32.Stealer.rti removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment