Spy Trojan

Trojan-Spy.Win32.Stealer.cmei removal

Malware Removal

The Trojan-Spy.Win32.Stealer.cmei is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.cmei virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Trojan-Spy.Win32.Stealer.cmei?


File Info:

name: 195B710F40BA72B655A8.mlw
path: /opt/CAPEv2/storage/binaries/1a406dafcaac78c91e0bf41714f7ec776f789b13ea178004f4eb455fa919f9df
crc32: 60DE10A9
md5: 195b710f40ba72b655a87e702134c6f5
sha1: 08a50dc1b5906038157056c43082c7b850b31a2c
sha256: 1a406dafcaac78c91e0bf41714f7ec776f789b13ea178004f4eb455fa919f9df
sha512: 640cba8172701171d96021df04327c095ba3a2ff34ffdd500031a01b8dcade6a3b6ef9f4be22459125be4b718005bc12496e563c3610d7482da57196ab5c3a02
ssdeep: 196608:qBRFWcVWQX4FJG58zc/8IJzSIKWt7lKEYmK+eO42FQuA3v9OVSp:qwccTJG2zG8IJSnWxlKEYmK+H/U9Oc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C296332AB5C124B3C6A957F6B662E9397A953DE00B7982DBF3E0758FC8101D4C931B31
sha3_384: 9a3c20d158da1273b50988255db8c8902cfc22e30e324fcf13277cdc05d8db2963c0333d6ee09de8182c3a5dc0dbc96e
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.cmei also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.195b710f40ba72b6
McAfeeArtemis!195B710F40BA
CylanceUnsafe
SangforTrojan.Win32.Agent.V3bp
K7AntiVirusTrojan ( 00595a1c1 )
BitDefenderTrojan.GenericKDZ.91274
K7GWTrojan ( 00595a1c1 )
Cybereasonmalicious.1b5906
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HQDK
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.cmei
MicroWorld-eScanTrojan.GenericKDZ.91274
RisingMalware.SwollenFile!1.DDB4 (CLASSIC)
VIPRETrojan.GenericKDZ.91274
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
APEXMalicious
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D1648A
GDataWin32.Trojan.PSE.69757
Acronissuspicious
VBA32Trojan.MSIL.InfoStealer.gen.U
ALYacTrojan.GenericKDZ.91274
MAXmalware (ai score=89)
PandaTrj/CI.A
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Spy.Win32.Stealer.cmei?

Trojan-Spy.Win32.Stealer.cmei removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment