Trojan

About “Trojan:Win32/PonyStealer.VD!MTB” infection

Malware Removal

The Trojan:Win32/PonyStealer.VD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/PonyStealer.VD!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/PonyStealer.VD!MTB?


File Info:

crc32: C1FF5552
md5: 2e962c398c33c953b7b6b378b43b0fbc
name: june29o.exe
sha1: d0d881870387d8b4eca4c38d926e0f70936d3bb0
sha256: 847e6e648faea4806d78b506419588d3aa8577b87f90d45638645b6d3da54e90
sha512: 50a0d0d5ae77a485126827a9605d3723bb68948073c5fa6bba181c9bdc21d55680d75da9dd71701fe9c3c580ae1a330bd4a539fb954b77f54c890c0fb5df3e8b
ssdeep: 12288:BjnGLjIup+Q67pPhPc3IAMXOvIHoFdDRVmqOJ1UVSMaBhDD/PHTUYt7px2:BjoUuGNhPc3uOIoScVSlBBD4YtFx2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/PonyStealer.VD!MTB also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Zusy.307899
FireEyeGeneric.mg.2e962c398c33c953
McAfeeFareit-FTB!2E962C398C33
MalwarebytesTrojan.MalPack.DLF
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Zusy.307899
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTROJ_FRS.VSNW1DF20
BitDefenderThetaGen:NN.ZelphiF.34130.@GW@aiSSxqhi
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.EMNH
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Zusy.307899
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Injector!1.AFE3 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zusy.307899 (B)
F-SecureTrojan.TR/Injector.robzu
DrWebTrojan.PWS.Siggen2.51176
Invinceaheuristic
SophosTroj/Delp-DQ
IkarusTrojan.Inject
CyrenW32/Trojan.LYIT-8047
AviraTR/Injector.robzu
Antiy-AVLTrojan/Win32.Sonbokli
MicrosoftTrojan:Win32/PonyStealer.VD!MTB
ArcabitTrojan.Zusy.D4B2BB
AhnLab-V3Trojan/Win32.Injector.R342334
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
CynetMalicious (score: 100)
VBA32BScope.TrojanPSW.Stealer
ALYacGen:Variant.Zusy.307899
Ad-AwareGen:Variant.Zusy.307899
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.VSNW1DF20
TencentWin32.Trojan.Kryptik.Hupy
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_85%
FortinetW32/Injector.ELXR!tr
AVGWin32:Malware-gen
Cybereasonmalicious.70387d
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.469

How to remove Trojan:Win32/PonyStealer.VD!MTB?

Trojan:Win32/PonyStealer.VD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment