Trojan

Trojan:MSIL/Stelega.DK!MTB (file analysis)

Malware Removal

The Trojan:MSIL/Stelega.DK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Stelega.DK!MTB virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/Stelega.DK!MTB?


File Info:

crc32: CDC313E6
md5: 597402481c5e696d7fc155e9b8855771
name: 597402481C5E696D7FC155E9B8855771.mlw
sha1: 71f5fec965bd4b440ea8692fd5c6df356a3f0163
sha256: 59395518c1daad6b8f63ee71ad7a5dbbf79f718fddcc2932fc9bd99a4820b32e
sha512: d7bb96ce8c4e5d6c53262a2fe1c33840b248e12ebfa8365f861f60821934125919b99f5ab3f2c2c6f5baf8a85f0d125355b3c41b176d4346dc694ede39ae1d36
ssdeep: 12288:G6zalveIP2Pouc9fqWbTfHX8CbiGKtV2pnZ3/8sEXdr:Lpr
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Unanimous.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Unanimous.exe

Trojan:MSIL/Stelega.DK!MTB also known as:

K7AntiVirusTrojan ( 0057db3b1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.109
CynetMalicious (score: 100)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.4e49e0db
K7GWTrojan ( 0057db3b1 )
Cybereasonmalicious.965bd4
CyrenW32/MSIL_Kryptik.ENZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ABNH
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Packed.Bulz-9867398-0
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.GenericKD.37130682
MicroWorld-eScanTrojan.GenericKD.37130682
Ad-AwareTrojan.GenericKD.37130682
SophosMal/Generic-S + Troj/MSIL-RGQ
BitDefenderThetaGen:NN.ZemsilF.34758.ym1@a8aJfqo
TrendMicroTROJ_GEN.R002C0RFL21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.597402481c5e696d
EmsisoftMalCert.A (A)
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Stelega.DK!MTB
GDataMSIL.Trojan-Stealer.NetSteal.BC4K14
AhnLab-V3Trojan/Win.Generic.C4527753
Acronissuspicious
McAfeeArtemis!597402481C5E
MAXmalware (ai score=86)
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0RFL21
RisingTrojan.MalCert!1.D6FA (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Kryptik.ABKY!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/Stelega.DK!MTB?

Trojan:MSIL/Stelega.DK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment