Spy

About “Keydoor.Spyware.Stealer.DDS” infection

Malware Removal

The Keydoor.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Keydoor.Spyware.Stealer.DDS virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Keydoor.Spyware.Stealer.DDS?


File Info:

name: 161DA8E6BD28B13ECF28.mlw
path: /opt/CAPEv2/storage/binaries/40a332519a879dee85fdfb8da8c966fa94f43f5acd750203e59e86d3e25ace40
crc32: 6DFB7B69
md5: 161da8e6bd28b13ecf289b9dcee77741
sha1: 0df98b81d8e2f55c7e12d768a46d93aadda94bea
sha256: 40a332519a879dee85fdfb8da8c966fa94f43f5acd750203e59e86d3e25ace40
sha512: 91f170325994ade1e7ec74cf1f83d01b6fb29c709b8d6fb165531001ffdc7560e6dd9dc6d74b761f3622dfc6d67e5b867fb0116daf85638248349c47e596c9e0
ssdeep: 1536:uvUvE3qz4ayX9ioT5Xl8lQWj1vTo5G6kvBzodfjZp4ZDp/naRRU:PC79l86WqGzIfjZpSDp/naRRU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147F39D11B881C577C04A94711499D2B2AB3DBA312A799983F3CC1B7B5FB13D0663E39B
sha3_384: 8c90df1b9fceabc03222487974d6fcd168579d624663d6987a0344fcc8db018873564ced8fb8a25ca118bb9e74f86ac1
ep_bytes: e8ea650000e978feffff8bff558bec51
timestamp: 2012-07-26 18:49:30

Version Info:

0: [No Data]

Keydoor.Spyware.Stealer.DDS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94611
FireEyeGeneric.mg.161da8e6bd28b13e
CAT-QuickHealTrojan.Dynamer.8881
McAfeeUrsnif-FQRW!161DA8E6BD28
MalwarebytesKeydoor.Spyware.Stealer.DDS
VIPRETrojan.GenericKDZ.94611
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKDZ.94611
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.6bd28b
ArcabitTrojan.Generic.D17193
BitDefenderThetaGen:NN.ZexaF.36196.jqY@aa!ewbg
CyrenW32/S-00d1a144!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Spy.Keydoor.AD
APEXMalicious
ClamAVWin.Malware.Scar-9776391-0
KasperskyTrojan.Win32.Scar.ojnn
AlibabaBackdoor:Win32/Rifdoor.195c
NANO-AntivirusTrojan.Win32.TrjGen.drufdw
ViRobotBackdoor.Win32.Agent.106526
AvastWin32:BackDoor-AFV [Trj]
RisingSpyware.Keydoor!1.B6A0 (CLASSIC)
EmsisoftTrojan.GenericKDZ.94611 (B)
BaiduWin32.Trojan.Agent.avd
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen6.34441
ZillyaTrojan.Katusha.Win32.38343
TrendMicroTrojanSpy.Win32.KEYDOOR.SM
McAfee-GW-EditionBehavesLike.Win32.Ursnif.ct
Trapminemalicious.high.ml.score
SophosTroj/Backdr-NR
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.beovz
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Spy.Keydoor.AA@82pvo3
MicrosoftTrojan:Win32/Vindor!pz
ZoneAlarmTrojan.Win32.Scar.ojnn
GDataTrojan.GenericKDZ.94611
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Scar.R565946
Acronissuspicious
VBA32Trojan.Scar
ALYacTrojan.GenericKDZ.94611
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.KEYDOOR.SM
TencentTrojan.Win32.Scar.16000293
YandexTrojan.GenAsa!kMCqdEG3U64
IkarusTrojan.Win32.Agent
FortinetW32/Agent.XFS!tr
AVGWin32:BackDoor-AFV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Keydoor.Spyware.Stealer.DDS?

Keydoor.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment