Trojan

Should I remove “Trojan:Win32/Estiwir.C”?

Malware Removal

The Trojan:Win32/Estiwir.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Estiwir.C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Estiwir.C?


File Info:

name: B876DF88BB39020501E4.mlw
path: /opt/CAPEv2/storage/binaries/8f2821bc4b19f32205578916c31937f14f48f76c57cee66d7077773dde839641
crc32: 905121E1
md5: b876df88bb39020501e4990fddf12187
sha1: 18ae5492b5181398f94fdcfefbe80df17c0c7229
sha256: 8f2821bc4b19f32205578916c31937f14f48f76c57cee66d7077773dde839641
sha512: f6f938942d7d8ccf166982f66eb2728df47601384d1ab2a15ed2f6a8b6e8412ce164bb6da05bb85951e6877ed981820892f953c21e13e320b635f99fcc8295db
ssdeep: 3072:UT9zjiI3H3CeQ75DxCjWyGlJpklF/hXa0dEXFC0c:UT9zG0XZQtDxlyqMrdE19c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10304D0D38E205C6DEC474A3118B7E73E753196400D908DEAF79ADD696CB67A12A0B20F
sha3_384: d4476fc0afa316ecd6a6d1a2b43f89e6c833e81e9703bdcfaf5780fc629ba1a654ea4a48858f6ef5354e5bbd87b19532
ep_bytes: 682f9a4200e8b47502007441ab909090
timestamp: 2015-05-01 09:14:43

Version Info:

CompanyName: Tencent
FileDescription: 腾讯QQ
FileVersion: 6.9.13791.0
LegalCopyright: Copyright (C) 1999-2015 Tencent. All Rights Reserved
ProductName: 腾讯QQ
ProductVersion: 6.9.13791.0
Translation: 0x0804 0x04b0

Trojan:Win32/Estiwir.C also known as:

LionicTrojan.Win32.Scar.luuu
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.56323
MicroWorld-eScanTrojan.GenericKD.38909012
FireEyeGeneric.mg.b876df88bb390205
ALYacTrojan.GenericKD.38909012
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaBackdoor:Win32/Farfli.077bb67f
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34212.lq1@a8y20lhb
CyrenW32/Trojan.LBIX-6238
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BXDE
TrendMicro-HouseCallTROJ_GEN.R002C0DB722
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Farfli.bxcx
BitDefenderTrojan.GenericKD.38909012
TencentWin32.Backdoor.Farfli.Pgcs
Ad-AwareTrojan.GenericKD.38909012
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DB722
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
EmsisoftTrojan.GenericKD.38909012 (B)
IkarusTrojan.Win32.Patched
GDataWin32.Trojan.Agent.HUTBHM
JiangminDownloader.LMN.hjw
AviraHEUR/AGEN.1204969
Antiy-AVLTrojan/Generic.ASMalwS.350C699
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Estiwir.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.BackDoor.C4957650
Acronissuspicious
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Androm
MalwarebytesMalware.AI.1814369006
APEXMalicious
RisingBackdoor.Farfli!8.B4 (CLOUD)
YandexBackdoor.Farfli!+Q/UPOOqm1Q
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_86%
FortinetW32/Injector.BXDE!tr
PandaTrj/GdSda.A

How to remove Trojan:Win32/Estiwir.C?

Trojan:Win32/Estiwir.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment