Malware

Win32/DataStealer.B malicious file

Malware Removal

The Win32/DataStealer.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DataStealer.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Win32/DataStealer.B?


File Info:

name: 99DCE63D90F8BAF388D4.mlw
path: /opt/CAPEv2/storage/binaries/87596388b3958bb169e67cf1241ae3becd52a2614e03c17f8baf782e416880c6
crc32: 618A23A8
md5: 99dce63d90f8baf388d43f17f18aef06
sha1: 04c9cfcb7970dcbfd93d4e181d084cbae4a4656b
sha256: 87596388b3958bb169e67cf1241ae3becd52a2614e03c17f8baf782e416880c6
sha512: 1f619a655e9d87700b0018e068486bca65724a59d80c4326e4a12f311a2fee5d24fff91a68eddc7de1b2b90d5095a46cc9c02fbbb5da99a92831f74cacfd0a10
ssdeep: 24576:18h4aPlfTUYDrQOfseBC1+ZnoBzEgY5cfPtQE3WV9UKkjhmKiKSqSWLQPgIpBe7H:11U9T8ZDYWntr3WVajE4IDVGi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A859D61FBCAC0F6DE4B12B41466D72FAFB1831857356AE363902F4959B32D1AC36318
sha3_384: a272f9439c7738c8a8840db3f5cec15ec0fa6a44b3a4382e4937d4fb140465bd7ac3effb5fd9cf5dbf589c051fef7fdd
ep_bytes: e8525e0000e978feffff6a1068c83c57
timestamp: 1999-12-18 03:06:54

Version Info:

0: [No Data]

Win32/DataStealer.B also known as:

BkavW32.FamVT.VirseTIT.Trojan
LionicVirus.Win32.Virut.mCAF
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Dropper.UYL
FireEyeGeneric.mg.99dce63d90f8baf3
CAT-QuickHealW32.Virut.G
ALYacTrojan.Dropper.UYL
CylanceUnsafe
ZillyaDropper.Agent.Win32.87415
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0030c2e21 )
AlibabaWorm:Win32/Stalk.af7d7395
K7GWPassword-Stealer ( 0030c2e21 )
Cybereasonmalicious.d90f8b
BaiduWin32.Trojan.DataStealer.b
CyrenW32/DataStealer.A.gen!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/DataStealer.B
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1372491
KasperskyWorm.Win32.Stalk.a
BitDefenderTrojan.Dropper.UYL
NANO-AntivirusTrojan.Win32.Dorifel.ewfwkj
SUPERAntiSpywareTrojan.Agent/Gen-DataStealer
AvastWin32:Vitro [Inf]
TencentTrojan.Win32.Dropper.abl
Ad-AwareTrojan.Dropper.UYL
SophosMal/Generic-R + Troj/Enosch-A
ComodoTrojWare.Win32.DataStealer.B@4xd7lu
DrWebTrojan.DownLoader5.50084
VIPREWorm.Win32.Enosch.a (v)
TrendMicroWORM_SILLY.SMRP
McAfee-GW-EditionBehavesLike.Win32.PUPXAX.th
EmsisoftTrojan.Dropper.UYL (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.bgle
AviraTR/Patched.Ren.Gen
MicrosoftWorm:Win32/Enosch!atmn
GDataTrojan.Dropper.UYL
CynetMalicious (score: 100)
AhnLab-V3HEUR/Fakon.mwf.X1352
Acronissuspicious
McAfeeSpy-Agent.gg
MAXmalware (ai score=88)
VBA32Trojan.Downloader
MalwarebytesWorm.Agent
TrendMicro-HouseCallWORM_SILLY.SMRP
RisingWorm.Win32.FakeFolder.bq (CLASSIC)
YandexTrojan.GenAsa!uMTwPhbSHs4
IkarusWorm.Win32.Enosch
MaxSecureTrojan.Scar.OICH
FortinetW32/CoinMiner.F
BitDefenderThetaAI:FileInfector.C2A5779617
AVGWin32:Vitro [Inf]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/DataStealer.B?

Win32/DataStealer.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment