Spy

Should I remove “RedlineStealer.Spyware.Stealer.DDS”?

Malware Removal

The RedlineStealer.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RedlineStealer.Spyware.Stealer.DDS virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Binary compilation timestomping detected

How to determine RedlineStealer.Spyware.Stealer.DDS?


File Info:

name: EB50CFEFFEA98752C892.mlw
path: /opt/CAPEv2/storage/binaries/5f290053d69f2b5324e2eda8712bde5c0e97763a081abd14cb6036cac13832f9
crc32: 64B3AE70
md5: eb50cfeffea98752c89204f0c9102e4a
sha1: d7cd804d768cc4d6de722cd6e9045f9982988656
sha256: 5f290053d69f2b5324e2eda8712bde5c0e97763a081abd14cb6036cac13832f9
sha512: 87376b1a28928409ee217c3644e0ecaea889feb70547ddd35b16aec73d9980b40117405fc5d453ddb061de3a946d2c4a05569e7d7159d8e8d7de8572960919bb
ssdeep: 3072:5xqZWTHaJIppUXS38IieCe98hjnxNn2pU9f2MKTV/wi4lr55R9TxlnsPsUw0jOun:rqZHXS3H78h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15914C51437FCCD11E1BA1A3F6961A05046BF9802AD42F25B76C767CD0E32B40F95BAA3
sha3_384: 082e6dc5f1916f7255e2fa7799f2dab90eeb6ad9cbd0fbe0e79bcd4ce6637c24700a50a550c292be432dfafaa4d325ce
ep_bytes: 55011280e807151255011280e0071512
timestamp: 2091-02-11 23:09:18

Version Info:

0: [No Data]

RedlineStealer.Spyware.Stealer.DDS also known as:

LionicTrojan.Win32.Generic.4!c
ElasticWindows.Trojan.RedLineStealer
ClamAVWin.Trojan.Generic-9933689-0
FireEyeGeneric.mg.eb50cfeffea98752
McAfeeGenericRXUW-QH!EB50CFEFFEA9
Cylanceunsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.d768cc
BitDefenderThetaGen:NN.ZexaF.36318.mmY@a4ybcNc
VirITTrojan.Win32.Agent.DPSF
CyrenW32/MSIL_Troj.CND.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
TencentTrojan-Psw.Win32.Stealer.16000501
F-SecureTrojan.TR/AD.RedLineSteal.davqx
DrWebTrojan.PWS.Stealer.35770
McAfee-GW-EditionBehavesLike.Win32.Generic.dt
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.MX2JV5
AviraTR/AD.RedLineSteal.davqx
ViRobotTrojan.Win.Z.Stealer.204800
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.QH.R544919
Acronissuspicious
MalwarebytesRedlineStealer.Spyware.Stealer.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H06GO23
RisingStealer.Agent!1.DC63 (CLASSIC)
IkarusTrojan-Spy.RedLineStealer
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Stealer.3577!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove RedlineStealer.Spyware.Stealer.DDS?

RedlineStealer.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment