Spy Trojan

TrojanSpy:Win32/Stelega.MR!MTB malicious file

Malware Removal

The TrojanSpy:Win32/Stelega.MR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Stelega.MR!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanSpy:Win32/Stelega.MR!MTB?


File Info:

crc32: 5CAE60A2
md5: 1c1b39f2909b87bd7bc8648856bb65be
name: 1C1B39F2909B87BD7BC8648856BB65BE.mlw
sha1: 6741ab4b68118cd4fb24315a219ecf701fc988e1
sha256: 28f478d2b7cac0587aaec26a787678375f74e0d16690eac6bf1d9cf5083b650f
sha512: 88e7e2218917c2fceaccd0122ecb9b72cd61c105aabedb26879d770564a37d0fc51724bf425f6349ca6ade14014a86eb9f7b18aa2f645ed1eed69b6b219c699c
ssdeep: 6144:H2yl43wFnxUHKsSO0tiXbPvbTT4nhnne4VX2pClCmgBaGYArphY3:H2yTk734hnvgpfmhGvq
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Stelega.MR!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.338705
FireEyeGeneric.mg.1c1b39f2909b87bd
Qihoo-360HEUR/QVM20.1.352F.Malware.Gen
ALYacGen:Variant.Mikey.116597
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Zusy.338705
Cybereasonmalicious.b68118
CyrenW32/Kryptik.CJT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.LokiBot-9789787-0
Ad-AwareGen:Variant.Zusy.338705
DrWebTrojan.Siggen9.48175
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionGenericRXMN-FI!1C1B39F2909B
EmsisoftGen:Variant.Zusy.338705 (B)
MAXmalware (ai score=89)
MicrosoftTrojanSpy:Win32/Stelega.MR!MTB
ArcabitTrojan.Zusy.D52B11
GDataGen:Variant.Zusy.338705
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Noon.C4222917
Acronissuspicious
McAfeeGenericRXMN-FI!1C1B39F2909B
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.HHHK
RisingTrojan.Kryptik!1.CE8B (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HHHM!tr
BitDefenderThetaGen:NN.ZexaF.34590.uuZ@aOQI!Im
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanSpy:Win32/Stelega.MR!MTB?

TrojanSpy:Win32/Stelega.MR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment