Trojan

Trojan.Win32.CookiesStealer.b removal instruction

Malware Removal

The Trojan.Win32.CookiesStealer.b is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.CookiesStealer.b virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

ip-api.com
www.facebook.com

How to determine Trojan.Win32.CookiesStealer.b?


File Info:

crc32: B5957184
md5: 8cbde3982249e20a6f564eb414f06fe4
name: 8CBDE3982249E20A6F564EB414F06FE4.mlw
sha1: 6d040b6c0f9d10b07f0b63797aa7bfabf0703925
sha256: 4a8a37d0010b2a946e9b202ea07d8b93a29a3ea9a56852678307076e10999c83
sha512: d84863489b5fb2d17ee1df47de735a88d510bb8f5e378126243e34edb017d3ed82807c7dbd5cf6a977601f0e440be12e680679f1ce472619fd0ebbe9579c3e1b
ssdeep: 24576:/xzKv7KEPLM1Nq1zYqa2p2yOxzTNkdBAnlXG6+Z1mbX:I9PLM1Nq1EqVp25PkUlXF+Z1I
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.CookiesStealer.b also known as:

BkavW32.Ekstak3220VHA.Trojan
K7AntiVirusTrojan ( 005723511 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.29982
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Cookiesstealer
McAfeeGenericRXAA-AA!8CBDE3982249
CylanceUnsafe
ZillyaTrojan.CookiesStealer.Win32.57
SangforTrojan.Win32.Stealer.KA
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/CookiesStealer.82365e16
K7GWTrojan ( 005723511 )
Cybereasonmalicious.82249e
CyrenW32/CookieStealer.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACLN
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Spyagent-9830839-0
KasperskyTrojan.Win32.CookiesStealer.b
BitDefenderTrojan.GenericKD.45873741
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
MicroWorld-eScanTrojan.GenericKD.45873741
TencentMalware.Win32.Gencirc.10ce37f6
Ad-AwareTrojan.GenericKD.45873741
SophosMal/Generic-S
ComodoMalware@#ycyz7jtgjl8y
BitDefenderThetaGen:NN.ZexaF.34688.8uW@aepbNMij
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0PC121
McAfee-GW-EditionBehavesLike.Win32.PUP.dc
FireEyeGeneric.mg.8cbde3982249e20a
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Scar.nra
WebrootW32.Malware.Gen
AviraTR/AD.JazoStealer.bxblq
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2FFCE3E
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftTrojan:Win32/Stealer.KA!MTB
GridinsoftTrojan.Win32.Agent.vb
AegisLabTrojan.Win32.CookiesStealer.4!c
ZoneAlarmTrojan.Win32.CookiesStealer.b
GDataTrojan.GenericKD.45873741
AhnLab-V3Trojan/Win32.RL_Infostealer.R356907
VBA32BScope.Trojan.Infospy
MAXmalware (ai score=85)
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R06CC0PC121
RisingStealer.Facebook!1.CC5B (CLOUD)
YandexTrojan.CookiesStealer!rzjo2BopPos
IkarusTrojan.Malagent
MaxSecureTrojan.Malware.109370897.susgen
FortinetW32/Agent.VHO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.CookiesStealer.b?

Trojan.Win32.CookiesStealer.b removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment