Spy Trojan

Trojan-Spy.Win32.Stealer.vra removal guide

Malware Removal

The Trojan-Spy.Win32.Stealer.vra is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.vra virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Spy.Win32.Stealer.vra?


File Info:

crc32: ECE03F77
md5: 75d6419dd436bd70086b6a5b1579853b
name: 75D6419DD436BD70086B6A5B1579853B.mlw
sha1: f691633d53eef6acea8f5f5dc4a8d5432d3b3d02
sha256: f09d143add8bd571bf78d5f5181122ba84c10eb9a6427d6f61279ffccf4bec69
sha512: 9af08954c0052533bb2eea078d0488455f928cb8f3aa53c6c4cbb9a3693058b45c385aa8fbca37f348cde0f5ff500a342021771775bb0a832d088eb645b3904d
ssdeep: 6144:f6FZZ5cIIuEsP4cosqIaT0wm3gnJBt4rWXvaHQT:f6TZ5cIIuEsP4c0Ia4HwZIeawT
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationz

Trojan-Spy.Win32.Stealer.vra also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45226852
FireEyeGeneric.mg.75d6419dd436bd70
ALYacTrojan.GenericKD.45226852
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45226852
K7GWRiskware ( 0040eff71 )
CyrenW32/Kryptik.CVF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan-Spy.Win32.Stealer.vra
AlibabaTrojanSpy:Win32/Stealer.caa17c4b
ViRobotTrojan.Win32.Z.Agent.283136.LD
TencentWin32.Trojan-spy.Stealer.Ajlu
Ad-AwareTrojan.GenericKD.45226852
EmsisoftTrojan.GenericKD.45226852 (B)
ComodoMalware@#3e35cj6dc05lw
F-SecureTrojan.TR/Kryptik.zcvce
DrWebTrojan.Siggen11.56832
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
AviraTR/Kryptik.zcvce
KingsoftWin32.Troj.Stealer.v.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MU!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B21B64
ZoneAlarmTrojan-Spy.Win32.Stealer.vra
GDataTrojan.GenericKD.45226852
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Glupteba.R361367
Acronissuspicious
McAfeeRDN/RedLineStealer
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILR
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_84%
FortinetW32/Kryptik.HGHW!tr
BitDefenderThetaGen:NN.ZexaF.34700.rmGfaeed3whc
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Spy.Win32.Stealer.vra?

Trojan-Spy.Win32.Stealer.vra removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment