Spy Trojan

Trojan:Win32/SpyStealer.AP!MTB removal tips

Malware Removal

The Trojan:Win32/SpyStealer.AP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyStealer.AP!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/SpyStealer.AP!MTB?


File Info:

name: EB08CD3D6EEA3434C2BC.mlw
path: /opt/CAPEv2/storage/binaries/64980f933948ff08493a7e2754057470440bd579ac2a9f4769f1a67966a42edf
crc32: 331BEF98
md5: eb08cd3d6eea3434c2bc561921f87364
sha1: 3a3fa1e70d62cd31abdfd4f104ead5bc7bb3846d
sha256: 64980f933948ff08493a7e2754057470440bd579ac2a9f4769f1a67966a42edf
sha512: d633b852093d05c4a744ccb7908595746768a217f199b79420a730e3215f385c23bc6abad08d8b45d0a8e82e7a6c94ab1831dd27d9ee23af5c0ca538ae2a220a
ssdeep: 24576:MaUsTnqIMvUkUTHy3AJ9FfuzLr+ZFsCUM1mQEoMkcLGGIlnf7zyqy9YUmFcH00Q0:NUhl3AJ9FfuzP+ZFBB16yyGGId7zrUmQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T181555BA39301531EE3937435C0DCAE35710A56312A2F7C97AB041BAADB3B2D16974F6B
sha3_384: 7d139201f687b24a40915e457589656bea2cb6f3046a842d1934e85dbf7dba0b335fe561b1922fc983db27a19d1b8182
ep_bytes: e867060000e974feffff558bec8b4508
timestamp: 1970-01-01 00:05:29

Version Info:

0: [No Data]

Trojan:Win32/SpyStealer.AP!MTB also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
McAfeeTrojan-FUMR!EB08CD3D6EEA
CylanceUnsafe
CyrenW32/Kryptik.GOC.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPFH
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.423685
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
MicroWorld-eScanGen:Variant.Zusy.423685
RisingTrojan.Generic@AI.99 (RDML:otsWYcE2mdJzmNEhhF91vg)
Ad-AwareGen:Variant.Zusy.423685
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PWS.Siggen3.15868
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.eb08cd3d6eea3434
EmsisoftGen:Variant.Zusy.423685 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.423685
JiangminTrojanSpy.Stealer.uda
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Zusy.D67705
MicrosoftTrojan:Win32/SpyStealer.AP!MTB
AhnLab-V3Trojan/Win.Generic.R491483
Acronissuspicious
VBA32BScope.Trojan.Sabsik
ALYacGen:Variant.Zusy.423685
MAXmalware (ai score=82)
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
TencentTrojan-Psw.Win32.Reline.16000435
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HPFH!tr
BitDefenderThetaGen:NN.ZexaF.34712.uvY@aGDnbId
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/SpyStealer.AP!MTB?

Trojan:Win32/SpyStealer.AP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment