1 of 2
Danger level 7
Type: Trojans
Common infection symptoms:
  • Slow Computer
  • System crashes
  • Connects to the internet without permission
  • Installs itself without permissions
  • Can't be uninstalled via Control Panel


Have you recently installed the StressPaint application from a random website on the web? If so, there is a huge possibility that a malicious application has been installed on your computer too. While the program itself works quite well, i.e. it allows users to draw whatever they like in order to relieve stress, the Trojan infection that is installed next to it might bring you a ton of problems. Unfortunately, users find out about its presence when it is already too late, i.e. when cyber criminals already have their private information in their hands. Yes, the StressPaint Trojan has been developed to steal personal information. It was first detected in the middle of April, 2018, and it has affected more than 35 000 users from Russia, Pakistan, Indonesia, Ukraine, Vietnam, and other countries since then. It is quite sophisticated malware because it not only drops files in %TEMP%, but also places an entry in the Run registry key so that it could continue working on the affected computer even after the system restart. Because of this, its removal will not be a piece of cake too. Of course, the malicious application must be removed from the system no matter what.

While the drawing program itself works well, the Trojan infection installed next to it does not do anything good. As research conducted by specialists working at pcthreat.com has shown, it only needs information from Google Chrome (e.g. login data and session cookies) so that it could get victims’ logins. At the time of research, it was mainly interested in Facebook credentials. Also, it tried to get such information as the number of friends, whether there are pages a victim manages, etc. According to researchers, there is a huge possibility that it might try to get logins of other popular websites, e.g. Amazon too in the future. If you do not want to experience more privacy-related problems, you must delete StressPaint Trojan as soon as possible. We cannot promise that it will be very easy to do this because it drops files in %TEMP%. You should find DX.exe and updata.dll there, but filenames might change. What else research has shown is that this malicious application makes modifications in the Run registry. This will allow it to start working when the Windows OS loads up. In other words, you will not disable it by restarting your computer.

It has been observed that users are the ones responsible for the appearance of the StressPaint Trojan infection on their computers. They allow this threat to enter their computers by downloading the drawing application from some kind of dubious website on the web. Of course, they do not know that they agree with the installation of the Trojan infection as well. There are plenty of different infections that might illegally enter your system, so you should not leave your computer unprotected. The installation of a reputable security tool is what you should do the first thing to prevent malware, but it does not mean that you can act carelessly. Security specialists say that users should never download programs from dubious websites. Also, they do not allow them to click on random links and advertisements promoting “useful software.” Finally, users should install new applications with great care, according to them. If you do as they say, we are sure you will not encounter a new malicious application ever again.

The removal of StressPaint Trojan is a must if you do not want to experience privacy-related problems. As you already know, this infection is used to steal users’ login credentials, and we can assure you that it will not disable itself anytime soon. This infection is quite sophisticated, so do not expect its manual removal to be very quick and easy. First, you need to kill all malicious processes. Then, you will have to delete malicious files from %TEMP% together with the malicious file launched. Finally, you will need to remove the entry belonging to StressPaint Trojan from the Run registry key. If you find this procedure too difficult, you can remove this Trojan from your system with an antimalware scanner instead.

How to delete StressPaint

  1. Access Task Manager (tap Ctrl+Shift+Esc), open the Processes tab, and kill suspicious processes one by one.
  2. Open Windows Explorer.
  3. Type %TEMP% in the URL bar and press Enter.
  4. Delete DX.exe and updata.dll (files might have different names).
  5. Delete the malicious file opened.
  6. Close Explorer and launch Run (tap Win+R).
  7. Navigate to HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run.
  8. Right-click on Updata (this Value might be named differently) and select Delete.
  9. Empty Recycle bin.
Download Spyware Removal Tool to Remove* StressPaint
  • Quick & tested solution for StressPaint removal.
  • 100% Free Scan for Windows

Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.