Trojan

How to remove “TrojanDownloader:Win32/Stegvob.A”?

Malware Removal

The TrojanDownloader:Win32/Stegvob.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Stegvob.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VMware through the presence of a file
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Stegvob.A?


File Info:

crc32: 451A01FC
md5: adc54be3eaeaf1d1348d73a1024bedfc
name: ADC54BE3EAEAF1D1348D73A1024BEDFC.mlw
sha1: 3c970de8073bf96117f363ac96298bafe88b6e13
sha256: 207db9f2c488fc5f4d1a6389537d60d5d50bed2b3b20933bde020e4bf040039f
sha512: f694203167ed1e926da90d31281251c3af81523700d983de73f3de680bce0daf1adbfc20b269a513d053a7c486a693c8e76e0d48e731b554dabd05a369aa7fea
ssdeep: 768:RireQqu11UwsyFUlVCmK8Q15MuHuBtXXZxYhS3UTmi3Yetkh7ulbvNu:RiqsFQVCmK95TOBtHbY0kqKeuljNu
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: nssdbm3
FileVersion: 3.12.9.0 Basic ECC
CompanyName: Mozilla Foundation
ProductName: Network Security Services
ProductVersion: 3.12.9.0 Basic ECC
FileDescription: Legacy Database Driver
OriginalFilename: nssdbm3.dll
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/Stegvob.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Dapato.b!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Ibank.312
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.449276
CylanceUnsafe
ZillyaDropper.Dapato.Win32.252
AlibabaVirTool:Win32/Obfuscator.cda26d61
Cybereasonmalicious.3eaeaf
CyrenW32/Bredolab.AW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BCVA
APEXMalicious
AvastWin32:Nedsym-CB [Trj]
ClamAVWin.Trojan.Agent-405891
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.449276
NANO-AntivirusTrojan.Win32.Meredrop.gjmdd
MicroWorld-eScanGen:Variant.Razy.449276
TencentWin32.Trojan-dropper.Dapato.Lqyn
Ad-AwareGen:Variant.Razy.449276
SophosML/PE-A + Troj/Agent-RNY
ComodoMalware@#aallhwmbj4gu
BitDefenderThetaGen:NN.ZexaF.34294.dmKfa0O8oci
VIPRETrojan.Win32.Meredrop
McAfee-GW-EditionPWS-Zbot.gen.axh
FireEyeGeneric.mg.adc54be3eaeaf1d1
EmsisoftGen:Variant.Buzy.3555 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen4
eGambitGeneric.PSW
Antiy-AVLTrojan/Generic.ASMalwS.18DD3C4
MicrosoftTrojanDownloader:Win32/Stegvob.A
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV[Zbot]
GDataGen:Variant.Razy.449276
AhnLab-V3Win-Trojan/FakeAV53.Gen
Acronissuspicious
McAfeeArtemis!ADC54BE3EAEA
MAXmalware (ai score=100)
VBA32BScope.Trojan.Zbot.01367
PandaTrj/Banker.JJG
IkarusTrojan-Spy.Zbot
FortinetW32/Kryptik.HZ!tr
AVGWin32:Nedsym-CB [Trj]
Paloaltogeneric.ml

How to remove TrojanDownloader:Win32/Stegvob.A?

TrojanDownloader:Win32/Stegvob.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment