Spy

Fignotok.Spyware.Stealer.DDS removal

Malware Removal

The Fignotok.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fignotok.Spyware.Stealer.DDS virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Harvests cookies for information gathering
  • Clears web history
  • Uses suspicious command line tools or Windows utilities

How to determine Fignotok.Spyware.Stealer.DDS?


File Info:

name: CDD4F90D36BB8B8E57B8.mlw
path: /opt/CAPEv2/storage/binaries/1dc4896132a3da0f3b451e28fc63ad75dad3c42c5b2351be2faf7c4b93c23496
crc32: 0677442A
md5: cdd4f90d36bb8b8e57b8a95272abbc23
sha1: ccdeb3b0cf818b883f5ee1d5a07d499f3655f955
sha256: 1dc4896132a3da0f3b451e28fc63ad75dad3c42c5b2351be2faf7c4b93c23496
sha512: f1bdc7bc1a62aa2430a2bed7dd3e2beebb5bc7d13e612199b01f9deeadd71c0bb9a36c02bee2ed0cfe7b099bcfab723cc3f25721e322984989e41d765e3b441c
ssdeep: 98304:qsCM2zGvJVV9rvE9rvN9rv29rvgnOJcnOJ4o66UeUAoZOkwKD+sI3NGJtVMDV0wx:kChVHvKvfvUv51b666OkwK7I3UMx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BC6BF8163A06E95D16D4E3CC49BB12783F07609A700C7FBEAC49D8E3E175F859397A2
sha3_384: 33121c18194f0e33307838010ed4596203edcb69b1fb6224575b711c1d6d437640231cae759eeb6eedba6f50674aa470
ep_bytes: 558bec6aff68b883da006874ea470064
timestamp: 2022-11-19 15:44:50

Version Info:

0: [No Data]

Fignotok.Spyware.Stealer.DDS also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Doina.41866
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Packed.Win32.Vemply.gen
BitDefenderGen:Variant.Doina.41866
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Doina.41866
EmsisoftGen:Variant.Doina.41866 (B)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
DrWebTrojan.BtcMine.1580
VIPREGen:Variant.Doina.41866
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.cdd4f90d36bb8b8e
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.16DVGAX
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.FlyStudio.a
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Doina.DA38A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win.Malware-gen.R525486
Acronissuspicious
MalwarebytesFignotok.Spyware.Stealer.DDS
RisingPUF.Vemply!8.132B5 (TFE:5:dE6XYf1FKAC)
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34796.@xW@a8NHT9fb
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.0cf818

How to remove Fignotok.Spyware.Stealer.DDS?

Fignotok.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment