Malware

How to remove “Win32/DataStealer.R”?

Malware Removal

The Win32/DataStealer.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DataStealer.R virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Harvests information related to installed mail clients

How to determine Win32/DataStealer.R?


File Info:

name: 7E6622BC4923B6AABFA6.mlw
path: /opt/CAPEv2/storage/binaries/28de6e912f6430b459c95e21f256a2b4fce5434e25cec75c6e953b98836b77f1
crc32: E8DC990F
md5: 7e6622bc4923b6aabfa68e098f2c08d8
sha1: 0101a2dcbf602f5ba44014261bdb0dcc1a4773eb
sha256: 28de6e912f6430b459c95e21f256a2b4fce5434e25cec75c6e953b98836b77f1
sha512: 7125325ef35212e493a6d77e53fafb68cc7ce7c9e37cea3cd3150b6c57877413fdb91bacb846a415ce0cbdb1197bcb40600690fff6150b686f2b49ab0037dde7
ssdeep: 196608:77ApWXrhE6b1lj/KIcuqpppJl2cJ8IfZMc9V5WeY/iELcOa8YQ3t3z6cbFyXRgD+:70pyrK6pl3cu2lpJ8IR9Tu/iELSPQ3ty
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BC6233FB328653ED4AE4B324AB396609C7B7B60691F8C1E17F0451CDF6A0701E3A656
sha3_384: 57fde6026eac0c95db83efae345b594e2bf9c39d0a91ca1839b88b0ea8350778a23643e4ec9498b38efa684c70733a5a
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: LmhSoft.com
FileDescription: Email Extractor for Windows 12.8 Installer
FileVersion: 12.8
LegalCopyright: © 2021 LmhSoft.com
OriginalFileName:
ProductName: Email Extractor for Windows
ProductVersion: 12.8
Translation: 0x0000 0x04b0

Win32/DataStealer.R also known as:

MicroWorld-eScanTrojan.GenericKD.37697127
FireEyeTrojan.GenericKD.37697127
ALYacTrojan.GenericKD.37697127
CylanceUnsafe
VIPRETrojan.GenericKD.37697127
K7AntiVirusPassword-Stealer ( 004df36d1 )
K7GWPassword-Stealer ( 004df36d1 )
ESET-NOD32a variant of Win32/DataStealer.R
BitDefenderTrojan.GenericKD.37697127
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.37697127
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.37697127 (B)
AviraTR/DataStealer.lzrac
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.37697127
CynetMalicious (score: 99)
McAfeeArtemis!7E6622BC4923
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R002H0CEA22
MaxSecureTrojan.Malware.183131205.susgen
FortinetW32/DataStealer.R!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/DataStealer.R?

Win32/DataStealer.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment