Trojan

What is “Trojan:MSIL/Stooten.A”?

Malware Removal

The Trojan:MSIL/Stooten.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Stooten.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan:MSIL/Stooten.A?


File Info:

crc32: C3935727
md5: 35b8bbd2d7b8dc34704053a5b7ccbb80
name: 35B8BBD2D7B8DC34704053A5B7CCBB80.mlw
sha1: a8a0da92c46df5616a2c8a38152f45533289a8f2
sha256: c0f9097147b5b58ec2cb6fed29c2fcc64357c81d5749a6d0b0547720bd51c79e
sha512: c1b366ec3b418dd9b2db9769966d90cd79b1661852f336de5d36132316a92103bf20c35771a8e9d158e6d596e7f2a3b933069597524e8e8541495093448445ee
ssdeep: 768:mZuzEP6aVYn6BMLtW7leQpb/E428Q63s2exwuCcVli9658A6LKamKat:Qwh6BMLtW7leovgastwuLli96ehDSt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: server.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: server.exe

Trojan:MSIL/Stooten.A also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.23119
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericFC.S18890150
ALYacGeneric.Malware.GJSDkg.BC76375A
CylanceUnsafe
ZillyaTrojan.Agent.Win32.96280
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Stooten.db1fb249
K7GWTrojan ( 700000121 )
Cybereasonmalicious.2d7b8d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Arcdoor.BE
APEXMalicious
AvastMSIL:AntiVM [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Malware.GJSDkg.BC76375A
NANO-AntivirusTrojan.Win32.MSILA.dclpsr
MicroWorld-eScanGeneric.Malware.GJSDkg.BC76375A
TencentWin32.Init.QQRob.uiy
Ad-AwareGeneric.Malware.GJSDkg.BC76375A
SophosML/PE-A + Mal/MSIL-A
ComodoMalware@#2cm563ua5w5ru
BitDefenderThetaGen:NN.ZemsilF.34670.cm0@a0AaqDk
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_PONTOEB.SMHA
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
FireEyeGeneric.mg.35b8bbd2d7b8dc34
EmsisoftGeneric.Malware.GJSDkg.BC76375A (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Agent.jbr
AviraBDS/Backdoor.Gen
eGambitGeneric.Dropper
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:MSIL/Stooten.A
ArcabitGeneric.Malware.GJSDkg.BCD12A57A
AegisLabTrojan.Win32.Agent.i!c
GDataGeneric.Malware.GJSDkg.BC76375A
McAfeeGenericRXCL-MJ!35B8BBD2D7B8
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1101191929
PandaGeneric Malware
TrendMicro-HouseCallBKDR_PONTOEB.SMHA
RisingBackdoor.Pontoeb!1.6637 (CLOUD)
IkarusTrojan-PWS.Win32.Agent
FortinetMSIL/Agent.SH!tr.pws
AVGMSIL:AntiVM [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Generic.HwMAOOYA

How to remove Trojan:MSIL/Stooten.A?

Trojan:MSIL/Stooten.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment