Spy Trojan

Trojan-Spy.Win32.Stealer.vqj malicious file

Malware Removal

The Trojan-Spy.Win32.Stealer.vqj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.vqj virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

iplogger.org
leatherbond.top
ip-api.com

How to determine Trojan-Spy.Win32.Stealer.vqj?


File Info:

crc32: 9A1F1288
md5: a911862b8e009e674d018aaff16a326b
name: A911862B8E009E674D018AAFF16A326B.mlw
sha1: 03537444d8d5fee6c3a86cd5ee86a33cba1deeca
sha256: add432dca76d9ae5e7883d7fccba10211cbf0a6b2f694af0edc37a679739f375
sha512: 903e7d5299d2c84f0a2cf2eeec77f48f0aaf0f0bb4947cddddca1667c0721b2ccb38c36573c125ef37f5bb33b9ab6003030fe2606db647d39c8bbab3ee090b02
ssdeep: 12288:in+xcJsrMvbdgQipycBRkVOT4UnqGQA6ca96PhKN/zT/dqy5/QdAG9Li4NpPThD:o8cJsrMvZgQAPBRB4Unqa6ca96PhgzM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Product: 1.7.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationz

Trojan-Spy.Win32.Stealer.vqj also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop16.3346
MicroWorld-eScanTrojan.GenericKD.35899386
FireEyeGeneric.mg.a911862b8e009e67
Qihoo-360Generic/HEUR/QVM11.1.38E6.Malware.Gen
ALYacTrojan.GenericKD.35899386
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35899386
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4d8d5f
CyrenW32/Kryptik.CVF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan-Spy.Win32.Stealer.vqj
AlibabaTrojanSpy:Win32/Stealer.bfb9f8bc
AegisLabTrojan.Win32.Malicious.4!c
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
Ad-AwareTrojan.GenericKD.35899386
EmsisoftTrojan.GenericKD.35899386 (B)
F-SecureTrojan.TR/Crypt.Agent.lltug
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
JiangminTrojan.Agent.dbjb
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.lltug
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MT!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D223C7FA
ZoneAlarmTrojan-Spy.Win32.Stealer.vqj
GDataTrojan.GenericKD.35899386
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361128
Acronissuspicious
McAfeeGenericRXAA-AA!A911862B8E00
MAXmalware (ai score=85)
VBA32Trojan.Agent
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HILM
TrendMicro-HouseCallTROJ_GEN.R002H0CLS20
TencentWin32.Trojan-spy.Stealer.Llgr
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_85%
FortinetW32/Kryptik.HGHW!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Spy.Win32.Stealer.vqj?

Trojan-Spy.Win32.Stealer.vqj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment