Spy Trojan

TrojanSpy:AndroidOS/seCvarPkg malicious file

Malware Removal

The TrojanSpy:AndroidOS/seCvarPkg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:AndroidOS/seCvarPkg virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • CAPE detected the Macoute malware family
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system

How to determine TrojanSpy:AndroidOS/seCvarPkg?


File Info:

name: 9792C458E2057400E730.mlw
path: /opt/CAPEv2/storage/binaries/2cbe7b40a626ec96f07acc725681c9a8177301904842824be54afe15321010e1
crc32: 64B9E236
md5: 9792c458e2057400e730257834783f16
sha1: 8084d6bfd50d607c086d7bbd958deeb372fff3a0
sha256: 2cbe7b40a626ec96f07acc725681c9a8177301904842824be54afe15321010e1
sha512: d29a3dbe15a3f80063f0e1d148dbaf45dcc47a62a5111f2bcc21f4ccf0afe3888bbf6b39642adf67f6107ba80b2c421f14aad2e44180941ce37f70aaadc348c3
ssdeep: 6144:rafsiVvAQ+tTm6cyERSiytj71crE4jKS6v9xE5Ki2C6O+hQQqPaO3pbI4+:YZvAQ+q6ctRt636rfjOfE5KTC0hQQiG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0C4D082EBC340F6D8930F71506BA37F9B725B0A902CDD96D7A42E56AC33313A91E754
sha3_384: b1616738308717422a9e90035f4d6a62d053cb7eed20808d5c57b9a19aab1b08e3e7b14da26d59d23117a0cac809b041
ep_bytes: 5589e583ec08c7042402000000ff15c0
timestamp: 2003-03-05 07:28:13

Version Info:

0: [No Data]

TrojanSpy:AndroidOS/seCvarPkg also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DCER
FireEyeGeneric.mg.9792c458e2057400
CAT-QuickHealTrojan.GenericPMF.S2958776
ALYacTrojan.Agent.DCER
K7AntiVirusEmailWorm ( 004df6bb1 )
K7GWTrojan ( 0057133c1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Agent.fl
CyrenW32/A-98aec620!Eldorado
SymantecW32.Pholdicon
ESET-NOD32Win32/Agent.NML
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Zusy-9889629-0
BitDefenderTrojan.Agent.DCER
NANO-AntivirusTrojan.Win32.Agent.erqhdu
SUPERAntiSpywareTrojan.Agent/Gen-Scar
AvastWin32:Vitro [Inf]
TencentTrojan.Win32.Keylogger.aa
Ad-AwareTrojan.Agent.DCER
SophosMal/Generic-R + Troj/Macoute-S
ComodoTrojWare.Win32.Scar.WRM@6hdckm
DrWebTrojan.DownLoader22.23546
TrendMicroWORM_MACOUTE.SMJ1
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftTrojan.Agent.DCER (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Scar.agsm
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1BF902
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojanSpy:AndroidOS/seCvarPkg
GDataWin32.Trojan.PSE.10XMVYJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R160138
Acronissuspicious
McAfeeW32/Worm-FTH!9792C458E205
MAXmalware (ai score=84)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.PasswordStealer
TrendMicro-HouseCallWORM_MACOUTE.SMJ1
RisingWorm.Macoute!1.A746 (CLASSIC)
YandexWorm.Agent!wqKmD1QAgIo
IkarusTrojan.Win32.Scar
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.F
BitDefenderThetaAI:Packer.D6F411331F
AVGWin32:Vitro [Inf]
Cybereasonmalicious.8e2057
PandaTrj/CI.A

How to remove TrojanSpy:AndroidOS/seCvarPkg?

TrojanSpy:AndroidOS/seCvarPkg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment