Spy Trojan

Trojan-Spy.Win32.Stealer.wgm removal

Malware Removal

The Trojan-Spy.Win32.Stealer.wgm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.wgm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.wgm?


File Info:

crc32: D6B3EAD4
md5: 10dec0664c0fb1f8de98ebf0879b16ce
name: 10DEC0664C0FB1F8DE98EBF0879B16CE.mlw
sha1: d4c8065fde28d334256d159295b5a4da92be2366
sha256: c34a85e738b7c8fa703aaa447cd24d17ff08baae5d4b44b7c2131c5df164b9a3
sha512: 4fcb9dc4663d31a48c43c02f202d06f8627f7bd57ba2ff74f3c2007401b3de0d60f2180bc34e42ad2c6968471b03b9988b5fb84f189f9928f3800a826c446684
ssdeep: 12288:RVXpC/dUgSUNIJxCR+i3jHgUcWPYJ902+jSXAnMIrkN7SW0n2pSChcR:RtpCFbSUNyxCR+ibX9YrD+2XYYY2d
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.10.27
TranslationUsa: 0x0173 0x00dc

Trojan-Spy.Win32.Stealer.wgm also known as:

DrWebTrojan.Siggen11.58078
MicroWorld-eScanTrojan.GenericKD.45428856
FireEyeGeneric.mg.10dec0664c0fb1f8
McAfeeRDN/Generic.dx
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575feb1 )
BitDefenderTrojan.GenericKD.45428856
K7GWTrojan ( 00575feb1 )
BitDefenderThetaGen:NN.ZexaF.34760.NmKfaeG2shdG
CyrenW32/Trojan.PYQA-9149
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIRF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.wgm
AlibabaTrojanSpy:Win32/Stealer.36622953
ViRobotTrojan.Win32.Z.Agent.646144.BS
RisingTrojan.Kryptik!8.8 (TFE:5:beSYtboWWOS)
Ad-AwareTrojan.GenericKD.45428856
SophosMal/Generic-S
ComodoMalware@#37pffdpx9evre
F-SecureTrojan.TR/AD.PredatorThief.ibtgg
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.GLUPTEBA.THAAABA
McAfee-GW-EditionBehavesLike.Win32.Trojan.jc
EmsisoftTrojan.GenericKD.45428856 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Stealer.dnn
WebrootW32.Trojan.Gen
AviraTR/AD.PredatorThief.ibtgg
MAXmalware (ai score=100)
Kingsoftwin32.unknown.virusname.(kcloud)
ArcabitTrojan.Generic.D2B53078
ZoneAlarmTrojan-Spy.Win32.Stealer.wgm
GDataTrojan.GenericKD.45428856
Acronissuspicious
VBA32BScope.Trojan.Azorult
ALYacTrojan.Glupteba.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.THAAABA
TencentWin32.Trojan-spy.Stealer.Dxxe
IkarusTrojan.Win32.Ranumbot
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HIRY!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.fde28d
AvastWin32:BotX-gen [Trj]
Qihoo-360Generic/HEUR/QVM11.1.88E2.Malware.Gen

How to remove Trojan-Spy.Win32.Stealer.wgm?

Trojan-Spy.Win32.Stealer.wgm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment