Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Trojan:Win32/LummaStealer.CADV!MTB removal guide

Published May 4, 2024 Trojan category 3 min read
Report context

What to verify before removal

Trojan:Win32/LummaStealer.CADV!MTB removal guide deserves a credential-safety review because this trojan label can overlap with remote access, browser data theft, or persistence after reboot. Cleanup should include scanning the file, removing the persistence point, and rotating exposed passwords from a clean device.

Start by comparing the local file name with 2F7B5B7EBA4311453C06.mlw, then review the behavior notes for credential theft, browser data access, remote-control activity, and persistence after reboot. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
2F7B5B7EBA4311453C06.mlw
  • Compare the suspicious file name with 2F7B5B7EBA4311453C06.mlw.
  • Confirm the detection name matches Trojan:Win32/LummaStealer.CADV!MTB removal guide before removing related files.
  • Review the report for credential theft, browser data access, remote-control activity, and persistence after reboot so the cleanup is based on observed behavior, not only the label.
  • After cleanup, rotate passwords from a clean device and review browser sessions or saved credentials.

The Trojan:Win32/LummaStealer.CADV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan:Win32/LummaStealer.CADV!MTB virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/LummaStealer.CADV!MTB?


File Info:

name: 2F7B5B7EBA4311453C06.mlw
path: /opt/CAPEv2/storage/binaries/10e23218873bdcebfcf959fca23b05531690ca38f184b6622a8cbf426ed81286
crc32: 0C1A8D38
md5: 2f7b5b7eba4311453c0687e7d1fd9ec5
sha1: df59e284de3c61d4bf43a22b695d514608b971c3
sha256: 10e23218873bdcebfcf959fca23b05531690ca38f184b6622a8cbf426ed81286
sha512: 50277ba52ae20fbeea6cc380da62ef391cd8a6557a03061a2a404d646b2fcc73029cf0d3f2df060639f3ba43b952b84113887fa9d038354d49f187911b88d952
ssdeep: 12288:HKp1N1IiXJ3Uxhtc0rQm6j6Hz7dZOg3ck45aAtqQEjnbuGSafzq1rBH:HKp1N1IiwthHtZHcsDbuLam1rBH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115B47E1574B3E0ACC11A34BA6948B324EF3E88C7435198F7E6648FF279229A15E75C37
sha3_384: 1bff7df4828d237eef9099f6b6dda97939af10f0557391751732009db6a24918414b1c7e69e641880d006079924fbf45
ep_bytes: 5589e5575683e4f889e6a148ac4500b9
timestamp: 2024-01-19 20:39:14

Version Info:

0: [No Data]

Trojan:Win32/LummaStealer.CADV!MTB also known as:

Bkav W32.Common.AD7ACD16
Lionic Trojan.Win32.LummaStealer.a!c
AVG Win32:SpywareX-gen [Trj]
Elastic Windows.Generic.Threat
MicroWorld-eScan Gen:Variant.Lazy.449542
FireEye Generic.mg.2f7b5b7eba431145
Skyhigh BehavesLike.Win32.Generic.hc
McAfee Artemis!2F7B5B7EBA43
Malwarebytes Trojan.Downloader
Zillya Trojan.Agent.Win32.3870444
Sangfor Spyware.Win32.Lummastealer.Vwrh
K7AntiVirus Spyware ( 005af7031 )
Alibaba TrojanDownloader:Win32/LummaStealer.28089082
K7GW Spyware ( 005af7031 )
BitDefenderTheta AI:Packer.A22EA8D71E
VirIT Trojan.Win32.Genus.UZD
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Spy.Agent.QLD
Cynet Malicious (score: 100)
APEX Malicious
Paloalto generic.ml
ClamAV Win.Infostealer.Lumma-10027222-0
Kaspersky HEUR:Trojan-Downloader.Win32.Zload.gen
BitDefender Gen:Variant.Lazy.449542
NANO-Antivirus Trojan.Win32.Zload.kkplnu
Avast Win32:SpywareX-gen [Trj]
Rising Spyware.Agent!8.C6 (TFE:3:mKdp3jyi9oN)
Emsisoft Gen:Variant.Lazy.449542 (B)
F-Secure Trojan.TR/Crypt.XPACK.Gen
DrWeb Trojan.PWS.Lumma.93
VIPRE Gen:Variant.Lazy.449542
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXECOZ
Trapmine malicious.high.ml.score
Sophos Mal/Generic-S
SentinelOne Static AI – Suspicious PE
Varist W32/Agent.ICN.gen!Eldorado
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=80)
Antiy-AVL Trojan[Downloader]/Win32.Zload
Kingsoft Win32.Trojan-Downloader.Zload.gen
Microsoft Trojan:Win32/LummaStealer.CADV!MTB
Arcabit Trojan.Lazy.D6DC06
ViRobot Trojan.Win.Z.Agent.523280
ZoneAlarm HEUR:Trojan-Downloader.Win32.Zload.gen
GData Gen:Variant.Lazy.449542
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5578021
VBA32 TrojanPSW.Lumma
ALYac Gen:Variant.Lazy.449542
Cylance unsafe
Panda Trj/GdSda.A
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXECOZ
Tencent Malware.Win32.Gencirc.11bd8f55
Yandex TrojanSpy.Agent!L3VK0SZkmh4
Ikarus Trojan-Spy.Win32.Agent
MaxSecure Trojan.Malware.82357917.susgen
Fortinet W32/Agent.QLD!tr
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:Win/LummaStealer.CADV!MTB

How to remove Trojan:Win32/LummaStealer.CADV!MTB?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.