Trojan

How to remove “Trojan.Win32.Staser.elgf”?

Malware Removal

The Trojan.Win32.Staser.elgf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Staser.elgf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive

How to determine Trojan.Win32.Staser.elgf?


File Info:

name: C78C0F1EA00A172FCF18.mlw
path: /opt/CAPEv2/storage/binaries/94e7dff98e35f362f7d6b2d72a4038b74f971dab57fdffc3bf1352d33d11cf27
crc32: 8FC4473B
md5: c78c0f1ea00a172fcf183e4885a4dd21
sha1: 1aae87fa6dec841c8ddd9f4ff51cb0c2d9f42b7d
sha256: 94e7dff98e35f362f7d6b2d72a4038b74f971dab57fdffc3bf1352d33d11cf27
sha512: 3127f7fae3d8c820d4c789c96cbc29fe5272ac7a29281c62b314890a32c7a23456d2e1f0fb3ba5a860b9db25cbce14527b1a7759f85c119b24234a2bd1274e64
ssdeep: 49152:I3dycB0XiwOVclkIL4v8NKAY3UF6H82fdAqlKZcQ3uS0zWuKn1JqZyMOYLs3QTv3:IQcBDCkm4GKAY4SAqccMuE/n+UMTjz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195D52342BCC594B1CA6258320B15BF206539BC705F19CDEF63E8566EED711C2E321BA7
sha3_384: 3995b69dc969eb521395afbd742cb91f910457c67616f95586a7e9af2173271f6f5a1129c8d48f428daca013dcd80337
ep_bytes: e8a4040000e988feffff3b0d68e64300
timestamp: 2021-04-07 14:39:21

Version Info:

0: [No Data]

Trojan.Win32.Staser.elgf also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47506130
FireEyeGeneric.mg.c78c0f1ea00a172f
McAfeeArtemis!C78C0F1EA00A
AlibabaTrojan:Win32/Staser.e3d9eefd
K7GWTrojan ( 004b8a501 )
ArcabitTrojan.Generic.D2D4E2D2
BitDefenderThetaGen:NN.ZedlaF.34062.7y8@amaQIifb
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Packed.NoobyProtect.G suspicious
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Staser.elgf
BitDefenderTrojan.GenericKD.47506130
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.47506130
SophosMal/Generic-S
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftTrojan.GenericKD.47506130 (B)
SentinelOneStatic AI – Malicious SFX
AviraTR/Staser.lfbzo
Antiy-AVLTrojan/Generic.ASBOL.C6B4
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Packed.NoobyProtect.B
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47506130
MAXmalware (ai score=88)
VBA32BScope.Adware.Agent
MalwarebytesMalware.AI.4096840667
RisingTrojan.Generic@ML.89 (RDML:ychxDyPOBuMZIqREk+deng)
YandexRiskware.NoobyProtect!RoYakSvuh98
IkarusPUA.NoobyProtect
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Staser.elgf?

Trojan.Win32.Staser.elgf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment