Trojan

Should I remove “Trojan.Win32.Staser.czmq”?

Malware Removal

The Trojan.Win32.Staser.czmq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Staser.czmq virus can do?

  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Staser.czmq?


File Info:

crc32: 22C1133C
md5: ec7b32d4598e5d8c1fde215836c73115
name: 6B.exe
sha1: e822609015c4d7a7bc8f863c38c4722c7e4e1248
sha256: 93821cacf9eb6ad879962cb4a88fe87a4df2f8a88f6bdff8926c3deaa3b20068
sha512: 436459cd4723db3e65ce58bc7adcd9422457207840a1039351032d7cc0a726a70de9e61d225790f3466e92ced0e51460f95c9d3193140ff02f19d12b8c553e40
ssdeep: 6144:2dZQbuwBzgxkSGi5qSdMm9+nMaK9+yuvVS5L+yTnT5kV8GPdkE20jYJ2ZNR4DF/v:SqKmOkSf5qEMM9oAPn+VhP+EPYJcs/tZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003
InternalName: RichEditGrid
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: RichEditGrid Application
ProductVersion: 1, 0, 0, 1
FileDescription: RichEditGrid MFC Application
OriginalFilename: RichEditGrid.EXE
Translation: 0x0409 0x04b0

Trojan.Win32.Staser.czmq also known as:

DrWebTrojan.DownLoader32.58773
MicroWorld-eScanTrojan.GenericKD.42338929
FireEyeTrojan.GenericKD.42338929
CAT-QuickHealTrojan.Staser
ALYacTrojan.Agent.Emotet
MalwarebytesTrojan.Emotet
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42338929
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R049C0DB620
CyrenW32/Agent.BND.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42338929
KasperskyTrojan.Win32.Staser.czmq
NANO-AntivirusTrojan.Win32.Kryptik.gyvuyc
ViRobotTrojan.Win32.Emotet.417792.D
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.42338929
F-SecureTrojan.TR/AD.Emotet.erwj
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Worm.gh
EmsisoftTrojan.GenericKD.42338929 (B)
IkarusTrojan-Banker.Emotet
JiangminTrojan.Staser.cmi
AviraTR/AD.Emotet.erwj
ArcabitTrojan.Generic.D2860A71
ZoneAlarmTrojan.Win32.Staser.czmq
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Malware/Win32.Generic.C3980508
McAfeeGenericRXAA-AA!EC7B32D4598E
MAXmalware (ai score=82)
VBA32Trojan.Staser
PandaTrj/Emotet.A
ESET-NOD32a variant of Win32/Kryptik.HAVN
TrendMicro-HouseCallTROJ_GEN.R049C0DB620
TencentWin32.Trojan.Staser.Ammd
FortinetW32/Kryptik.HAVN!tr
WebrootW32.Trojan.Gen
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.bb4

How to remove Trojan.Win32.Staser.czmq?

Trojan.Win32.Staser.czmq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment