Backdoor

Simda.Backdoor.Stealer.DDS removal

Malware Removal

The Simda.Backdoor.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Simda.Backdoor.Stealer.DDS virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Simda.Backdoor.Stealer.DDS?


File Info:

crc32: 837697CF
md5: c39e652b20ed4d0de6e6525c32ee71a5
name: C39E652B20ED4D0DE6E6525C32EE71A5.mlw
sha1: 573a7d613ce9065f8eed009c4fe4e8ad112b5f11
sha256: 18abd743b8deabc0a54c637231d35ed90748ce006d192393f7ee14e10b5a083b
sha512: afd17cb0feced3992453d518e45da3d4a911bb874c235f478ec5b9a181b115bdd7c855cfcad2af9fdbfb386d7b997cb362345c7a9addef6d228964df127253bb
ssdeep: 6144:K6p2sSxTrGvsFUejWyZr3hPswa1TZjxzF:KwaTbFUe5Zrxw3Z
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Simda.Backdoor.Stealer.DDS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.317803
CAT-QuickHealTrojan.Shifu
ALYacGen:Variant.Zusy.317803
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Malware.Shifu-6804440-0
K7AntiVirusSpyware ( 005228cb1 )
BitDefenderGen:Variant.Zusy.317803
K7GWSpyware ( 005228cb1 )
Cybereasonmalicious.b20ed4
CyrenW32/S-7a16e605!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Shifu-B [Trj]
ClamAVWin.Trojan.Shifu-6330434-1
KasperskyTrojan-Banker.Win32.Shifu.eph
NANO-AntivirusTrojan.Win32.Shiz.dvsrfy
ViRobotTrojan.Win32.Agent.168448.U
RisingRansom.Blocker!8.12A (TFE:dGZlOgLaeyYIjEMjGQ)
Ad-AwareGen:Variant.Zusy.317803
EmsisoftGen:Variant.Zusy.317803 (B)
ComodoTrojWare.Win32.Spy.Shiz.NCA@8m98i8
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop7.20629
ZillyaTrojan.Shifu.Win32.360
TrendMicroTROJ_GEN.R03BC0DBQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.c39e652b20ed4d0d
SophosML/PE-A + Troj/Shifu-I
IkarusTrojan-Banker.ShiFu
JiangminTrojan.Yakes.akc
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Upatre
GridinsoftTrojan.Win32.Packed.bot!s1
ArcabitTrojan.Zusy.D4D96B
ZoneAlarmTrojan-Banker.Win32.Shifu.eph
GDataWin32.Trojan-Spy.Shiz.D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Shifu.C2756321
Acronissuspicious
McAfeeGenericRXGM-ZQ!C39E652B20ED
MAXmalware (ai score=87)
VBA32TrojanBanker.Shifu
MalwarebytesSimda.Backdoor.Stealer.DDS
PandaTrj/Genetic.gen
ZonerTrojan.Win32.75090
ESET-NOD32Win32/Spy.Shiz.NCR
TrendMicro-HouseCallTROJ_GEN.R03BC0DBQ21
TencentMalware.Win32.Gencirc.10b0cf32
YandexTrojan.GenAsa!zlrAhKZjOyI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.42C3E4
BitDefenderThetaAI:Packer.6EB81FC01F
AVGWin32:Shifu-B [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM19.1.8E5B.Malware.Gen

How to remove Simda.Backdoor.Stealer.DDS?

Simda.Backdoor.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment