Trojan

Trojan:Win32/Stealerc.NS!MTB removal guide

Malware Removal

The Trojan:Win32/Stealerc.NS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Stealerc.NS!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Stealerc.NS!MTB?


File Info:

name: 645F6469F8A16381494D.mlw
path: /opt/CAPEv2/storage/binaries/43c8b8931f7105ef6b5b50a102a968fb838df0cb6ec153c4885be2cb3c0e60cb
crc32: 8DBA5356
md5: 645f6469f8a16381494d1c3474fce2b7
sha1: edb6c28116d62dfc654d000bea8d4be630586d7c
sha256: 43c8b8931f7105ef6b5b50a102a968fb838df0cb6ec153c4885be2cb3c0e60cb
sha512: c1b31b7eff84ea08656f4ac8871886e526a34b562fb445fea014b6fca9aba53044828e8ed48d94463441eba354389e213d13ca5490035f8fb17887e6d77734c3
ssdeep: 24576:loVsQmNw1bov27aDVS3RW8jn5uX1ERtDNpE:OKGbov27ao3RJuXIxE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B358D21F8C14172EEE210B742ECFE69426DA4B0071959DF22DD3BFED6506C26F3259A
sha3_384: 580287ea8224ef321b0ed9c7f53615379d4bf728e19701698779a0afe41a33ff8e44407f9656f1c002275d651d7e759d
ep_bytes: e918f90300e970ee0600e9927f0400e9
timestamp: 2023-11-02 12:34:18

Version Info:

0: [No Data]

Trojan:Win32/Stealerc.NS!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
DrWebTrojan.KillProc2.22173
MicroWorld-eScanTrojan.Inject.BFC
FireEyeTrojan.Inject.BFC
SkyhighBehavesLike.Win32.Sabsik.th
ALYacTrojan.Inject.BFC
VIPRETrojan.Inject.BFC
K7AntiVirusTrojan ( 005aa1da1 )
BitDefenderTrojan.Inject.BFC
K7GWTrojan ( 005aa1da1 )
VirITTrojan.Win32.GenusT.DTMS
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GMZA
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
NANO-AntivirusTrojan.Win32.Convagent.kdarii
RisingBackdoor.Agent!8.C5D (TFE:1:SQVxLVF5OHK)
SophosTroj/Krypt-ABY
F-SecureTrojan.TR/AD.Nekark.hpetm
TrendMicroTROJ_GEN.R002C0DK523
EmsisoftTrojan.Inject.BFC (B)
IkarusTrojan.Win32.Redline
MAXmalware (ai score=86)
GoogleDetected
AviraTR/AD.Nekark.hpetm
VaristW32/Kryptik.KNN.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
MicrosoftTrojan:Win32/Stealerc.NS!MTB
ArcabitTrojan.Inject.BFC
ViRobotTrojan.Win.Z.Inject.1149952.D
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.PSE.1FGYFE3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLine.R620138
McAfeeGenericRXAA-AA!645F6469F8A1
DeepInstinctMALICIOUS
MalwarebytesTrojan.MalPack.RND.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK523
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Stealerc.NS!MTB?

Trojan:Win32/Stealerc.NS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment