Spy

QQTen.Spyware.Stealer.DDS removal instruction

Malware Removal

The QQTen.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What QQTen.Spyware.Stealer.DDS virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine QQTen.Spyware.Stealer.DDS?


File Info:

name: 7F7128D5EE685C6D47E3.mlw
path: /opt/CAPEv2/storage/binaries/0fabd98c1f57fb295236d4bc60427f968486a69492cbf189ee9ea288a2108b23
crc32: 3E29BE5B
md5: 7f7128d5ee685c6d47e36ba93461753a
sha1: d7ff4805962b329e87804ec5fb553e5f23d4dbec
sha256: 0fabd98c1f57fb295236d4bc60427f968486a69492cbf189ee9ea288a2108b23
sha512: a5bac613b3f3f88a7d8318a60cae0c497c1d929fc065f543dff034e32263abc67ce2a3a0a23f2e2242f53e24c30838830f51a16486ece0fd473382804d8bc99c
ssdeep: 24576:4Wt2rUVv058EoBXpu8SXIXBkAmoLjGuRR3I:4EdCoBXjaIXs+R4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C65AE23F182C0F2C2061530596657F6EE35BE5EAE148B93B3A4FFAC1E32151D53729A
sha3_384: 52abff2d9b4f91bbd1530f604861abfa56746acd6a8b56654e741a7ae18e4c5a90403299e03f78ebf7ee7c4de6b70fd6
ep_bytes: 558bec6aff6838ef530068c431480064
timestamp: 2023-02-20 08:06:13

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

QQTen.Spyware.Stealer.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.muUy
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PWSIME.2
FireEyeGeneric.mg.7f7128d5ee685c6d
ALYacGen:Heur.PWSIME.2
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
AlibabaWorm:Win32/Siggen.074eafbb
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.5ee685
BitDefenderThetaGen:NN.ZexaF.36196.Cr0@aOydA3lb
CyrenW32/Trojan.GRW.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Worm.Autorun-5224
Kasperskynot-a-virus:UDS:RiskTool.Win32.IMEStartup.ah
BitDefenderGen:Heur.PWSIME.2
AvastWin32:TrojanX-gen [Trj]
SophosGeneric Reputation PUA (PUA)
BaiduWin32.Trojan.FakeIME.d
VIPREGen:Heur.PWSIME.2
TrendMicroTROJ_GEN.R011C0WBM23
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
Trapminesuspicious.low.ml.score
EmsisoftApplication.Generic (A)
IkarusTrojan.Siggen
GDataWin32.Trojan.PSE.15MOKEC
JiangminRiskTool.IMEStartup.fgx
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.PWSIME.2
ZoneAlarmnot-a-virus:UDS:RiskTool.Win32.IMEStartup.ah
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R366174
McAfeeGenericRXAA-AA!7F7128D5EE68
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesQQTen.Spyware.Stealer.DDS
TrendMicro-HouseCallTROJ_GEN.R011C0WBM23
RisingTrojan.Generic@AI.95 (RDML:bIyKTdoPsnV0AUb4OoZypQ)
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove QQTen.Spyware.Stealer.DDS?

QQTen.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment