Spy Trojan

TrojanSpy:Win32/Stealer.AJK!MSR information

Malware Removal

The TrojanSpy:Win32/Stealer.AJK!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Stealer.AJK!MSR virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/Stealer.AJK!MSR?


File Info:

crc32: 245ACE30
md5: b17326235c0b2fed917eb72c9631d9fb
name: B17326235C0B2FED917EB72C9631D9FB.mlw
sha1: 330fa1e841a12067a692e88e7fe5f2ab5f3d1929
sha256: 45406dae6b2c7383a3464de9112940cc9a388767fa867f17bc2a9c904861b358
sha512: a794964260848776d9538f284f69969e520f03565e94cb0ddbed53314978eee7aeb689c29746a5e8ff759ace9f24630a4c0906e1a2c2b02834936b51c80e30e7
ssdeep: 6144:INulCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTElo:2ulcXCeK4fM8mrc02NOrQlo
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Stealer.AJK!MSR also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72161
FireEyeGeneric.mg.b17326235c0b2fed
McAfeeW32/PinkSbot-HF!B17326235C0B
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.72161
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
CyrenW32/Trojan.PMOT-3247
SymantecTrojan.Maltrec.TS
ESET-NOD32a variant of Win32/Kryptik.HIKD
Paloaltogeneric.ml
ClamAVWin.Malware.Fbfk-9817495-0
KasperskyTrojan-Banker.Win32.RTM.gpn
AlibabaTrojanBanker:Win32/Stealer.77980b90
Ad-AwareTrojan.GenericKDZ.72161
SophosML/PE-A + Mal/EncPk-APV
ComodoMalware@#3dy8hb0ijf4q7
F-SecureTrojan.TR/Crypt.Agent.hexna
DrWebBackDoor.Qbot.568
TrendMicroTROJ_FRS.0NA103LN20
McAfee-GW-EditionW32/PinkSbot-HF!B17326235C0B
EmsisoftMalCert.A (A)
JiangminTrojan.Banker.RTM.tz
WebrootW32.Trojan.Qakbot
AviraTR/Crypt.Agent.hexna
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojanSpy:Win32/Stealer.AJK!MSR
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D119E1
AhnLab-V3Trojan/Win32.RL_Generic.R359732
ZoneAlarmTrojan-Banker.Win32.RTM.gpn
GDataTrojan.GenericKDZ.72161
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Qbot
ALYacTrojan.Agent.QakBot
MalwarebytesTrojan.TrickBot
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103LN20
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.HDNN!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
Qihoo-360Win32/Trojan.305

How to remove TrojanSpy:Win32/Stealer.AJK!MSR?

TrojanSpy:Win32/Stealer.AJK!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment