Worm

Cambot.Worm.Keylogger.DDS (file analysis)

Malware Removal

The Cambot.Worm.Keylogger.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cambot.Worm.Keylogger.DDS virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Cambot.Worm.Keylogger.DDS?


File Info:

crc32: 9A57B2BB
md5: 51080f07129c32157508b0cc873157da
name: 51080F07129C32157508B0CC873157DA.mlw
sha1: 1f9042011e0dbacc795d29ecd7e10ec78d93f17b
sha256: dd7a1d5e4641b87595fbc8abc0c4035c14105a416c099dc13564c350652ae4d1
sha512: 72ec862ffc84bba45b7b63ab68f36903c14d985b24f8876bdf1483ed0de74280ae9292033ef2c2ea79631321e0cf9313bcc47b955e4df189a7ba4d249717d588
ssdeep: 3072:qGVP1UNucgs7pVAzl7MVKLhViuHxAjwxnQ01So:qGVP+Nubs7pWzlYVKLriOxJnQ01
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 222
FileVersion: 1.00
CompanyName: jh
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: 222.exe

Cambot.Worm.Keylogger.DDS also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doris.2240
FireEyeGeneric.mg.51080f07129c3215
CAT-QuickHealTrojan.VBCrypt.MF.1942
Qihoo-360Win32/Trojan.698
ALYacGen:Variant.Doris.2240
CylanceUnsafe
VIPRETrojan.Win32.VBInject.pcb (v)
AegisLabWorm.Win32.VBNA.meIH
SangforMalware
K7AntiVirusTrojan ( 00570c1d1 )
BitDefenderGen:Variant.Doris.2240
K7GWTrojan ( 00570c1d1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/VBInject.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Bifrose.H!generic
APEXMalicious
AvastWin32:VB-ABYT [Trj]
ClamAVWin.Trojan.Refroso-7610302-0
KasperskyTrojan.Win32.Refroso.frav
AlibabaTrojan:Win32/Refroso.38f773b9
NANO-AntivirusTrojan.Win32.VB.qtdns
TencentWin32.Trojan.Refroso.Srdg
Ad-AwareGen:Variant.Doris.2240
SophosMal/Generic-S
ComodoTrojWare.Win32.Injector.dec@4mpx5r
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Injector.Win32.496212
TrendMicroCryp_SpyEye
McAfee-GW-EditionBehavesLike.Win32.Downloader.cz
EmsisoftGen:Variant.Doris.2240 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Refroso.fhm
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Refroso
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/VBInject.gen!EP
ArcabitTrojan.Doris.D8C0
ZoneAlarmTrojan.Win32.Refroso.frav
GDataGen:Variant.Doris.2240
CynetMalicious (score: 100)
McAfeeGeneric VB.fo
MalwarebytesCambot.Worm.Keylogger.DDS
PandaGeneric Malware
ESET-NOD32a variant of Win32/Bifrose.NLI
TrendMicro-HouseCallCryp_SpyEye
RisingMalware.Undefined!8.C (TFE:5:egdhzzYftFM)
YandexTrojan.GenAsa!nT9yGp2VZHo
IkarusWorm.Win32.VBNA
eGambitGeneric.Malware
FortinetW32/Bifrose.NKY!tr
BitDefenderThetaAI:Packer.4276D38520
AVGWin32:VB-ABYT [Trj]

How to remove Cambot.Worm.Keylogger.DDS?

Cambot.Worm.Keylogger.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment