Trojan

Trojan:Win32/StealerC.SPGA!MTB removal

Malware Removal

The Trojan:Win32/StealerC.SPGA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/StealerC.SPGA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Tswana
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/StealerC.SPGA!MTB?


File Info:

name: C352B482EBD638DA026C.mlw
path: /opt/CAPEv2/storage/binaries/89faad9e4c83bd704a0a1417cae6f422de9974732acf0803132e4c4517c0ae5b
crc32: B6DA4135
md5: c352b482ebd638da026c1686a043b3cd
sha1: 534b174c1f2b5de7735f8d981bdb23096b9884ee
sha256: 89faad9e4c83bd704a0a1417cae6f422de9974732acf0803132e4c4517c0ae5b
sha512: 71d08013c2c825a2cb07d6f539ac0719b15c52aab480a725664735eb82a9b0782a16573d5cde83e132bab8f6801b475b6f7ef4a479673c812332dbbe4df3771f
ssdeep: 3072:pCL+oO9LfUc53CKdyJiNIhQpzNBg5uKXnTu4W/mQ5j5I9kgQ4bRXp6AQAw:pCm9Lsc533bLJBvKXC4W/+bRXMA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170448D1136EDC032E3B355714634C3F01A7BB872A97595BE7AC02A690E35EE1AA34337
sha3_384: cfdc71ce83fce29a6cae153e072be9bb27763b69f42b409496c200db298907884c3097c1b26c21bc6f8dab1cf84931f9
ep_bytes: e81e870000e979feffff8bff558bec81
timestamp: 2022-12-03 17:15:04

Version Info:

FileVers: 91.5.67.57
ProductVespa: 66.2.79.16
InternalName: Heart
LegalCopyrighd: umbrellas
CompanyName: Samuel
Translation: 0x167c 0x0301

Trojan:Win32/StealerC.SPGA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.71016230
FireEyeGeneric.mg.c352b482ebd638da
CAT-QuickHealRansom.Stop.P5
SkyhighBehavesLike.Win32.Dropper.dh
McAfeeArtemis!C352B482EBD6
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005afe3a1 )
K7GWTrojan ( 005afe3a1 )
Cybereasonmalicious.c1f2b5
BitDefenderThetaGen:NN.ZexaF.36608.pu0@ayLZ!LnG
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HVUM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Filerepmalware-10017834-0
KasperskyTrojan.Win32.SelfDel.imtm
BitDefenderTrojan.GenericKD.71016230
NANO-AntivirusTrojan.Win32.SelfDel.kgfntx
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
SophosML/PE-A
F-SecureTrojan.TR/AD.Stealc.qfokn
DrWebTrojan.PWS.Stealer.38239
VIPRETrojan.GenericKD.71016230
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.71016230 (B)
IkarusTrojan.Win32.Crypt
VaristW32/Kryptik.LHM.gen!Eldorado
AviraTR/AD.Stealc.qfokn
Antiy-AVLTrojan/Win32.Sabsik
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/StealerC.SPGA!MTB
ArcabitTrojan.Generic.D43B9F26
ZoneAlarmTrojan.Win32.SelfDel.imtm
GDataWin32.Trojan.Agent.ING6IU
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R629778
VBA32Malware-Cryptor.Azorult.gen
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002H07LT23
RisingTrojan.Generic@AI.100 (RDML:BpRssk4WpIWcIzP9cD9VTA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.220061331.susgen
FortinetW32/GenKryptik.GSAT!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/StealerC.SPGA!MTB?

Trojan:Win32/StealerC.SPGA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment