Trojan

Trojan:Win32/Stealerc.NS!MTB malicious file

Malware Removal

The Trojan:Win32/Stealerc.NS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Stealerc.NS!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Stealerc.NS!MTB?


File Info:

name: 1D1651FC7B0E1B1A3C54.mlw
path: /opt/CAPEv2/storage/binaries/4b17c6e9096e51b71734daaa456cd7c39266bc3f62188467a4aa45116a39c25b
crc32: 86C02CCD
md5: 1d1651fc7b0e1b1a3c54990ceea8555c
sha1: fabed857af3b8a0c24eda1146eb4a2f2c9cdf256
sha256: 4b17c6e9096e51b71734daaa456cd7c39266bc3f62188467a4aa45116a39c25b
sha512: b98ab683d6565ed88ad2db8fd1180746b28ec635f2d7276fd6e465a877347c91d085b7ab2cca3347dc51e1878e00d0a4d602ff62b6c36b9131d2bc53f0a592c1
ssdeep: 12288:TJDm0NIl0xHm/3dm9aNlL5fpdhNbtQT9DX+ecruiTb5GqYPBNCTw2:tDm0NI+Hm/Nm9aNlNBNbKZOLCBm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB359E3178C58175EDF221B743ECF62682AE94B0C75955DF12D41AEED710AC2AF32B82
sha3_384: d6d4627b38ccbb51ea32c5b356224379331e57a0295a54e118b929bd10fd6e225a1ef09723b1571ca02d71efd3f1928a
ep_bytes: e9b02a0400e9eebe0500e92bb10400e9
timestamp: 2023-10-27 10:31:40

Version Info:

0: [No Data]

Trojan:Win32/Stealerc.NS!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.4697
FireEyeGen:Variant.Ser.Zusy.4697
SkyhighBehavesLike.Win32.Generic.th
ALYacGen:Variant.Mikey.157757
MalwarebytesTrojan.MalPack.RND
VIPREGen:Variant.Mikey.157757
K7AntiVirusTrojan ( 005aa09f1 )
BitDefenderGen:Variant.Ser.Zusy.4697
K7GWTrojan ( 005aa09f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ETFD
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Backdoor.Win32.Mokes.gen
AlibabaBackdoor:Win32/Stealerc.dd8036b7
NANO-AntivirusTrojan.Win32.Mokes.kctxxw
RisingBackdoor.Convagent!8.123DC (TFE:5:mRU6n37KkvD)
EmsisoftGen:Variant.Ser.Zusy.4697 (B)
F-SecureTrojan.TR/AD.Nekark.rtzpm
DrWebTrojan.Inject4.63442
SophosTroj/Krypt-ABY
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.12PQFKD
VaristW32/Kryptik.KNN.gen!Eldorado
AviraTR/AD.Nekark.rtzpm
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Ser.Zusy.D1259
ZoneAlarmHEUR:Backdoor.Win32.Mokes.gen
MicrosoftTrojan:Win32/Stealerc.NS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Evo-gen.C5364807
BitDefenderThetaGen:NN.ZexaF.36792.ezW@ay3Nhhk
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DJR23
TencentWin32.Backdoor.Mokes.Kqil
IkarusTrojan.Win32.Redline
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Stealerc.NS!MTB?

Trojan:Win32/Stealerc.NS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment