Spy

Spyware.PasswordStealer.Dropper removal guide

Malware Removal

The Spyware.PasswordStealer.Dropper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.PasswordStealer.Dropper virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Tamil
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Bochs through the presence of a registry key
  • Creates a copy of itself

How to determine Spyware.PasswordStealer.Dropper?


File Info:

name: D83BC96927F0AD5D7BF4.mlw
path: /opt/CAPEv2/storage/binaries/a882a555c1f408ef2075a94d456f3471fad8af76f4bf49b15a01e27c7402668b
crc32: F7F818F0
md5: d83bc96927f0ad5d7bf4242d0d1d0d28
sha1: a85345ee3cebc0adf7368d1ded263ff07477c287
sha256: a882a555c1f408ef2075a94d456f3471fad8af76f4bf49b15a01e27c7402668b
sha512: 4c47cd1febe0af4049baa0c8958c521da26d5d284386dba6626de8158ad444706787ae555de67e5e5deda542aa326a2486e73bdff1a3854a750ca2d47ad66a47
ssdeep: 3072:AFxVH0lBeN4V0AArak7fZ8tuTuJvjsyodEn3Pnp89NDDYzxJoudQSOx99EfkyAyz:salB+4Vc1Z8cu3Pp8gJVMW0yNNlhf0s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7441281F682FDD2FAD7827D40F6C198317B3AA417698A5075E6E7AEF8742C01C5D0A3
sha3_384: 42d9a5da2b9de5c39b0d7c59be4339e145188644a724c2020f9af05abf0faafbc8187c8097d5c07550dac19699f2400d
ep_bytes: 60be00d042008dbe0040fdff57eb0b90
timestamp: 2017-08-02 08:04:49

Version Info:

InternalName: venidedodu.exe
Translation: 0x0449 0x04b1

Spyware.PasswordStealer.Dropper also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanDeepScan:Generic.Mint.Zamg.8.8E7C57DC
FireEyeGeneric.mg.d83bc96927f0ad5d
McAfeeGenericRXAA-AA!D83BC96927F0
CylanceUnsafe
VIPREDeepScan:Generic.Mint.Zamg.8.8E7C57DC
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDeepScan:Generic.Mint.Zamg.8.8E7C57DC
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.927f0a
CyrenW32/ABRisk.SEMK-8160
SymantecPacked.Generic.534
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.GOZL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Gandcrab-6846115-0
KasperskyTrojan.Win32.Mucc.jgz
AlibabaTrojan:Win32/Skeeyah.4fd0b81d
NANO-AntivirusTrojan.Win32.Kryptik.fmimig
AvastWin32:Trojan-gen
RisingMalware.UDM!1.A89E (TFE:5:Qss1KcM4KhS)
Ad-AwareDeepScan:Generic.Mint.Zamg.8.8E7C57DC
SophosML/PE-A + Mal/GandCrab-G
ComodoMalware@#1jx0k7sxkurup
DrWebTrojan.DownLoader27.35216
ZillyaTrojan.Mucc.Win32.1282
TrendMicroRansom_GandCrab.R002C0CF322
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dc
Trapminemalicious.moderate.ml.score
EmsisoftDeepScan:Generic.Mint.Zamg.8.8E7C57DC (B)
IkarusTrojan.Win32.Krypt
GDataDeepScan:Generic.Mint.Zamg.8.8E7C57DC
JiangminTrojan.Chapak.bdj
WebrootW32.Adware.Installcore
GoogleDetected
AviraHEUR/AGEN.1213660
Antiy-AVLTrojan/Generic.ASMalwS.4FD0
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitDeepScan:Generic.Mint.Zamg.8.8E7C57DC
SUPERAntiSpywareTrojan.Agent/Gen-Chapak
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C2972953
VBA32BScope.Trojan.Chapak
ALYacDeepScan:Generic.Mint.Zamg.8.8E7C57DC
MAXmalware (ai score=100)
MalwarebytesSpyware.PasswordStealer.Dropper
TrendMicro-HouseCallRansom_GandCrab.R002C0CF322
TencentMalware.Win32.Gencirc.114d982f
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.CNB!tr
BitDefenderThetaGen:NN.ZexaF.34606.pmKfaa5tzGki
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Spyware.PasswordStealer.Dropper?

Spyware.PasswordStealer.Dropper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment