Threat Database Trojans Trojan.Stealer

Trojan.Stealer

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,574
Threat Level: 80 % (High)
Infected Computers: 24,419
First Seen: May 24, 2012
Last Seen: January 24, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Stealer

File System Details

Trojan.Stealer may create the following file(s):
# File Name MD5 Detections
1. taskmgr.exe f6f44d774e1cdeb8ff75c6314a99d548 465
2. NlmService.exe 1b440d416103418759155fbdbd314721 39
3. troj_generic_94ac75181094d9f9dc150b99011a0036cc0be513bdf87a70dcb3af08b3d6af9e.exe 8015e25459aa214bcd1697ab722a7ec9 1
4. file.exe 1a6455ff63137466cf365df239a43901 0
5. 104a961365504c44819b4e01af15c19d 104a961365504c44819b4e01af15c19d 0
More files

Registry Details

Trojan.Stealer may create the following registry entry or registry entries:
Regexp file mask
%ALLUSERSPROFILE%\antivir.exe
%ALLUSERSPROFILE%\infozam.exe
%ALLUSERSPROFILE%\IntellIJ.exe
%APPDATA%\Microsoft\steam.vbe
%LOCALAPPDATA%\AppVShNotifytvbs.vbs
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Microsoft\steam.vbe

Directories

Trojan.Stealer may create the following directory or directories:

%APPDATA%\Windows Manager Secuity Becap
%APPDATA%\steampch

Analysis Report

General information

Family Name: Trojan.Stealer
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 21858b4cb2dcb0fc005bb4221af6d1d5
SHA1: 822035faa84c50a4d22925dda183d395908333ed
SHA256: 1CC831645D2D6C7E87962E9D8EE0C697A6E60277ACFC71C10F5FA7501881C42D
File Size: 189.10 KB, 189096 bytes
MD5: 6203a9caa5ecb581227c43c194c5a2c7
SHA1: a8958001961665b99b6c35a16eb81bf2ef672875
SHA256: 9586520FC101D730A127361E16C46DF9EBF62B93B5C92A57DF7403460136CCA9
File Size: 83.97 KB, 83968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments http://www.bpsoft.com
Company Name BreakPoint Software, Inc.
File Description bpsregwd.dll
File Version
  • 5.0.2.3909
  • 4.20
Internal Name bpsregwd
Legal Copyright
  • Copyright (C) 1999-2004 BreakPoint Software, Inc. All rights reserved.
  • Copyright (C) 1999-2007 BreakPoint Software, Inc. All rights reserved.
Original Filename bpsregwd.dll
Product Name bpsregwd
Product Version
  • 5.0.2.3909
  • 4.20

Digital Signatures

Signer Root Status
BreakPoint Software, Inc. Thawte Code Signing CA Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • packed
  • x86

Block Information

Total Blocks: 843
Potentially Malicious Blocks: 0
Whitelisted Blocks: 807
Unknown Blocks: 36

Visual Map

0 ? 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\822035faa84c50a4d22925dda183d395908333ed_0000189096.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a8958001961665b99b6c35a16eb81bf2ef672875_0000083968.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...