Spy

Win32/Spy.Socelars.AD information

Malware Removal

The Win32/Spy.Socelars.AD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Socelars.AD virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Spy.Socelars.AD?


File Info:

crc32: D9EDC558
md5: f99210b5aa549a76265ea373622f2752
name: 002.exe
sha1: 41b958a5e5ae4f44a8398409b688eb4bfafebff2
sha256: f0f0d06ed47f872a1ce282327c6cd2881016b0275b13856befd06208d7e0a766
sha512: b7ef6f945eb4aab98e1ca06c4fd30ac2aa49c635c8808569c6daf964527c2d11b1710ae550b6c3c61a7d3ef379c1bd2dcb6337b4cef89b11c5ddf4df1fb672f6
ssdeep: 49152:nDI65YFyyegjAA95eV3DRubjQ5n/GWZO2oUeKBytE9gEZV1:DX5YFyyFjv5eV3DRubQZO2oUeKBy4g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: CopyRight (C) 2019
InternalName: ByteDownload
FileVersion: 1, 0, 0, 2
CompanyName: 003
ProductName: ByteDownload Application
ProductVersion: 1, 0, 0, 2
FileDescription: ByteDownload Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: 003.EXE
Translation: 0x0804 0x04b0

Win32/Spy.Socelars.AD also known as:

MicroWorld-eScanGen:Variant.Zusy.299743
FireEyeGen:Variant.Zusy.299743
McAfeeGenericRXJJ-JX!F99210B5AA54
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusTrojan ( 0055deeb1 )
BitDefenderGen:Variant.Zusy.299743
K7GWTrojan ( 0055deeb1 )
BitDefenderThetaGen:NN.ZexaF.34090.Bw0@aGl2dJej
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Zusy.299743
KasperskyTrojan.Win32.Staser.dbjq
AlibabaTrojanSpy:Win32/Staser.7ecab63e
RisingTrojan.Kryptik!1.C178 (CLOUD)
Ad-AwareGen:Variant.Zusy.299743
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1046656
TrendMicroTROJ_GEN.R002C0PBD20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
EmsisoftGen:Variant.Zusy.299743 (B)
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.IHWN-7401
MaxSecureTrojan.Malware.74833305.susgen
AviraHEUR/AGEN.1046656
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D492DF
ZoneAlarmTrojan.Win32.Staser.dbjq
MicrosoftTrojan:Win32/Occamy.C
VBA32Trojan.Wacatac
ALYacGen:Variant.Zusy.299743
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32Win32/Spy.Socelars.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PBD20
TencentWin32.Trojan.Staser.Efao
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.EAXO!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.f28

How to remove Win32/Spy.Socelars.AD?

Win32/Spy.Socelars.AD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment