Trojan

Should I remove “Trojan:Win32/Stealerc.NS!MTB”?

Malware Removal

The Trojan:Win32/Stealerc.NS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Stealerc.NS!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Stealerc.NS!MTB?


File Info:

name: 2FF34EEECBECFD050357.mlw
path: /opt/CAPEv2/storage/binaries/79aa42f14198d317ad4f3a0f79dbd104c6714ccc22ccb23e3f1e52ca7477b988
crc32: 8972D19C
md5: 2ff34eeecbecfd050357b0489e42610b
sha1: d58a8a60e5a9221086953dd63443ff382b56a78f
sha256: 79aa42f14198d317ad4f3a0f79dbd104c6714ccc22ccb23e3f1e52ca7477b988
sha512: f79e6eec31297f06c46fa01182ad1ff6a226140bfe59574b33289d156e17ba7d001d48518ff6a050ddc8d906eee5ef05602094e0aefa65a2303e1ef02134a6ba
ssdeep: 3072:BlQdL3eS0Fsz1ENTA4Ub1ZVzrKrg8Y951Sm8hSaYwWP5Cer2cN2j+mjXS2XSPyrf:S3e9qbtrKct9TjViPcNwX2s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136048E05B1DD40B1C9BA18380AF0E373EEBEB8544AD94DDF5BD40BBE5A2147CD22196A
sha3_384: d39e0a7e8678d3dcc402b8611b48b2321f4c750e9e85440ecc66e307bd9bf18541166286d752167b6ccc9c82bbd62b0d
ep_bytes: e8a3020000e97afeffff558bec8b4508
timestamp: 2023-11-01 20:06:34

Version Info:

0: [No Data]

Trojan:Win32/Stealerc.NS!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Lazy.4901
SkyhighBehavesLike.Win32.Generic.ch
MalwarebytesSpyware.Stealc
VIPREGen:Variant.Ser.Lazy.4901
BitDefenderGen:Variant.Ser.Lazy.4901
Cybereasonmalicious.0e5a92
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent_AGen.FO
APEXMalicious
ClamAVWin.Malware.Midie-10011372-0
KasperskyHEUR:Trojan-PSW.Win32.Convagent.gen
RisingTrojan.Generic@AI.100 (RDML:XG3mTUFmnuedGOG9EZt7/A)
SophosTroj/Mystic-D
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.2ff34eeecbecfd05
EmsisoftGen:Variant.Ser.Lazy.4901 (B)
IkarusTrojan.Win32.Stealerc
MAXmalware (ai score=86)
GoogleDetected
VaristW32/Stealer.FT.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Agent
Kingsoftmalware.kb.a.940
MicrosoftTrojan:Win32/Stealerc.NS!MTB
ArcabitTrojan.Ser.Lazy.D1325
ZoneAlarmHEUR:Trojan-PSW.Win32.Convagent.gen
GDataGen:Variant.Ser.Lazy.4901
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.36792.luX@aaT!1agi
ALYacGen:Variant.Ser.Lazy.4901
DeepInstinctMALICIOUS
VBA32BScope.TrojanPSW.Stealerc
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.FB!tr.dldr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Stealerc.NS!MTB?

Trojan:Win32/Stealerc.NS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment