Worm

What is “Worm:Win32/Stekct.A”?

Malware Removal

The Worm:Win32/Stekct.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Stekct.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Stekct.A?


File Info:

name: 7F281988FE9A8771CC99.mlw
path: /opt/CAPEv2/storage/binaries/d99628fdedf11ade7295874a895ae803345ffe2d92379ca8143be71766d5cf3a
crc32: 6C55CB7F
md5: 7f281988fe9a8771cc990f1b77d85b51
sha1: 06dc8fdc7014a797c5693649b858c3ba35a79d57
sha256: d99628fdedf11ade7295874a895ae803345ffe2d92379ca8143be71766d5cf3a
sha512: 5bb74b9a02e1c6eeae483db27bc91bf52a4d31f7fbe20ffee379c46181059949ead42d6919e670b0c59d8304dc539f73fa298037a77a427a3006fecf5f4e633f
ssdeep: 3072:AjGpvINzImDwW+e0lVektAXW+rzl3bD1uP6lFKPbtaokhM4AXQVoM9U5Q/:WaINhP05tl2lLswYWJ2Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F256E2405682107F9B5378BAA28C82D57DD4AC2A51B47C5EF32D2127BFE2A6331FD427
sha3_384: aa8252c4167f664e4959bf7eab1fd474190b9f4fa332303a4b0f7aa43a4676efeea6e98da323882ddb879d6383b2d19f
ep_bytes: 833d9ac142007e8b1546c04200755283
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Stekct.A also known as:

LionicTrojan.Win32.Agent.lz2Y
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.TDss.40
FireEyeGeneric.mg.7f281988fe9a8771
ALYacGen:Variant.TDss.40
ZillyaTrojan.Carberp.Win32.1412
SangforSuspicious.Win32.Save.a
AlibabaVirTool:Win32/Obfuscator.464b48e7
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34114.@JZ@aSe1zebi
VirITTrojan.Win32.Agent.DOM
CyrenW32/Kazy.BF.gen!Eldorado
SymantecPacked.Generic.382
ESET-NOD32Win32/Gyimface.A
BaiduWin32.Virus.Krap.a
TrendMicro-HouseCallTROJ_GEN.R002C0CL821
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.TDss.40
NANO-AntivirusTrojan.Win32.Gyimface.ulbqf
AvastWin32:Injector-AKP [Trj]
TencentWin32.Worm.Gyimface.Ajca
Ad-AwareGen:Variant.TDss.40
EmsisoftGen:Variant.TDss.40 (B)
ComodoApplicUnwnt.Win32.Hoax.ArchSMS.RXU@4nkp87
DrWebBackDoor.Spy.1543
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0CL821
McAfee-GW-EditionBehavesLike.Win32.PWSLegMir.vt
SophosML/PE-A + Troj/Spy-YO
APEXMalicious
GDataGen:Variant.TDss.40
JiangminTrojanSpy.Carberp.ati
WebrootW32.Malware.Heur
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.56F8B
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.TDss.40
ViRobotTrojan.Win32.Agent.196096.H
MicrosoftWorm:Win32/Stekct.A
SentinelOneStatic AI – Malicious PE
AhnLab-V3Spyware/Win32.Carberp.R20763
Acronissuspicious
McAfeePWS-Zbot.gen.ro
VBA32Trojan.Hider.2205
CylanceUnsafe
RisingWorm.Gyimface!8.AAF (CLOUD)
YandexTrojan.GenAsa!pDmxpxveiKg
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.ZVL!tr
AVGWin32:Injector-AKP [Trj]
Cybereasonmalicious.8fe9a8
PandaTrj/Pacrypt.D

How to remove Worm:Win32/Stekct.A?

Worm:Win32/Stekct.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment