Categories: Spy

KeyLogger.Spyware.Stealer.DDS (file analysis)

The KeyLogger.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What KeyLogger.Spyware.Stealer.DDS virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine KeyLogger.Spyware.Stealer.DDS?


File Info:

name: 77904F3E9708206566F8.mlwpath: /opt/CAPEv2/storage/binaries/a6e5bbe0dd849bd6dffa895e5b58c11ca63f1e360c7772b915dd3d3a191da8c9crc32: F52607B0md5: 77904f3e9708206566f828da0b679f51sha1: c58a8011cc5ea1f925799bdb353997f2ca6f3aa0sha256: a6e5bbe0dd849bd6dffa895e5b58c11ca63f1e360c7772b915dd3d3a191da8c9sha512: 482e36592c3c4c27818aa418356c38ee424a4776004a6f177d777b18924e031737f51ae7bc65f55c53a9109add6ab2012e0f9f9cafb3820fd5c04907dd899f7assdeep: 98304:sqsjoPxrK0PDF2s8ykXPZ3X+wPtXYWkAZ0N5c//////K8XdtlMnQJcB46owDXP6z:sBIUXdX+ctXDmqhl6XxVYtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T127766D22F604C6B7C22B6732285B4AF8A6B27D316F58124373D4AE1D7FB1B91F906711sha3_384: b71279c08f73cc5f7b256a476cbf1f134434455b9f9888db2e791566a331d380d5446a27edc6ee70191a2859f13cb262ep_bytes: a193565d00c1e002a397565d00526a00timestamp: 2005-03-23 17:51:08

Version Info:

0: [No Data]

KeyLogger.Spyware.Stealer.DDS also known as:

MicroWorld-eScan Trojan.GenericKD.67199766
CAT-QuickHeal Backdoor.Prorat.AZ2
Malwarebytes KeyLogger.Spyware.Stealer.DDS
Sangfor Backdoor.Win32.Prorat.Vuq7
K7AntiVirus Trojan ( 005850dc1 )
K7GW Trojan ( 005850dc1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Win32.Backdoor.Prorat.e
VirIT Trojan.Win32.Small.ANV
Cyren W32/Banload.B.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 multiple detections
APEX Malicious
ClamAV Win.Trojan.Delf-1540
Kaspersky Backdoor.Win32.Prorat.191
BitDefender Trojan.GenericKD.67199766
NANO-Antivirus Trojan.Win32.Prorat.dleg
Avast Win32:Prorat-HJ [Trj]
Rising Backdoor.Prorat!1.A068 (CLASSIC)
Emsisoft Trojan.GenericKD.67199766 (B)
F-Secure Backdoor.BDS/Lurpen.rts
DrWeb BackDoor.ProRat.19
VIPRE Trojan.GenericKD.67199766
TrendMicro TROJ_SPNR.38KH13
McAfee-GW-Edition BackDoor-AVW
FireEye Generic.mg.77904f3e97082065
Sophos Mal/HckPk-A
SentinelOne Static AI – Suspicious PE
GData Win32.Trojan.Agent.GULHLS
Jiangmin TrojanDropper.Mudrop.czc
Google Detected
Avira BDS/Lurpen.rts
Antiy-AVL Trojan[Backdoor]/Win32.Prorat
Arcabit Trojan.Generic.D4016316
ViRobot Trojan.Win.Z.Prorat.7229440.A
ZoneAlarm Backdoor.Win32.Prorat.191
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Backdoor/Win.Prorat.R580364
McAfee BackDoor-AVW
MAX malware (ai score=80)
VBA32 Backdoor.Prorat
Cylance unsafe
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TROJ_SPNR.38KH13
Tencent Malware.Win32.Gencirc.11a2b06b
Ikarus Backdoor.Win32.Prorat
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/NDAoF.38KH13!tr
AVG Win32:Prorat-HJ [Trj]
Cybereason malicious.1cc5ea
DeepInstinct MALICIOUS

How to remove KeyLogger.Spyware.Stealer.DDS?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Trojan.Win32.Agent.xbmhyp removal

The Trojan.Win32.Agent.xbmhyp is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Worm.Win32.Vobfus.devu (file analysis)

The Worm.Win32.Vobfus.devu is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

Win32.Worm.Viking.NCO (B) removal

The Win32.Worm.Viking.NCO (B) is considered dangerous by lots of security experts. When this infection is…

34 mins ago

Generic.Dacic.94CCEEA9.A.512EF93D (B) removal tips

The Generic.Dacic.94CCEEA9.A.512EF93D (B) is considered dangerous by lots of security experts. When this infection is…

39 mins ago

About “Generic.Dacic.8952383F.A.D38CAD9C” infection

The Generic.Dacic.8952383F.A.D38CAD9C is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

About “Trojan-Spy.Win32.Zbot.zruy” infection

The Trojan-Spy.Win32.Zbot.zruy is considered dangerous by lots of security experts. When this infection is active,…

56 mins ago