Spy Trojan

Should I remove “Trojan-Spy.Win32.Stealer.wac”?

Malware Removal

The Trojan-Spy.Win32.Stealer.wac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.wac virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.wac?


File Info:

crc32: 59D239C2
md5: 8016a2439b4f6c3a919fcbea61615b21
name: 8016A2439B4F6C3A919FCBEA61615B21.mlw
sha1: 7619ef641117ca576075f09d7815864af6effec2
sha256: 36e2d47f3667ec11a9853dbc29f67599970b96f16692a6212757d3b7410de34c
sha512: 340b05653b6a3e6821add4d9ba50e33eedd1921e06751b7d99deab80881f13330b4217b513ec5c82b601492047ec550d3c87814ffa6725b9ad3010739d07f008
ssdeep: 6144:4O2AEAI7Cxhw3tS1KAo6YN8H5RlR5Bp85jGZH8ZuL74tJ3:4qbI7CxG9iTP08Hv5B25j/ZuLEtJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acc
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.0.16
TranslationUsa: 0x0273 0x007d

Trojan-Spy.Win32.Stealer.wac also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.8016a2439b4f6c3a
McAfeeArtemis!8016A2439B4F
CylanceUnsafe
SangforMalware
Cybereasonmalicious.41117c
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan-Spy.Win32.Stealer.wac
RisingBackdoor.Tofsee!8.1E9 (TFE:5:Phpgg42YJEG)
F-SecureHeuristic.HEUR/AGEN.1140248
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
SophosML/PE-A
AviraHEUR/AGEN.1140248
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.D3!ml
ZoneAlarmTrojan-Spy.Win32.Stealer.wac
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34742.umKfaqXTuWmG
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIPD
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/GenKryptik.ERHN!tr
WebrootW32.Trojan.Glupteba
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.729B.Malware.Gen

How to remove Trojan-Spy.Win32.Stealer.wac?

Trojan-Spy.Win32.Stealer.wac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment