Trojan

Trojan:Win32/LummaStealer.CADV!MTB removal guide

Malware Removal

The Trojan:Win32/LummaStealer.CADV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LummaStealer.CADV!MTB virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/LummaStealer.CADV!MTB?


File Info:

name: 2F7B5B7EBA4311453C06.mlw
path: /opt/CAPEv2/storage/binaries/10e23218873bdcebfcf959fca23b05531690ca38f184b6622a8cbf426ed81286
crc32: 0C1A8D38
md5: 2f7b5b7eba4311453c0687e7d1fd9ec5
sha1: df59e284de3c61d4bf43a22b695d514608b971c3
sha256: 10e23218873bdcebfcf959fca23b05531690ca38f184b6622a8cbf426ed81286
sha512: 50277ba52ae20fbeea6cc380da62ef391cd8a6557a03061a2a404d646b2fcc73029cf0d3f2df060639f3ba43b952b84113887fa9d038354d49f187911b88d952
ssdeep: 12288:HKp1N1IiXJ3Uxhtc0rQm6j6Hz7dZOg3ck45aAtqQEjnbuGSafzq1rBH:HKp1N1IiwthHtZHcsDbuLam1rBH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115B47E1574B3E0ACC11A34BA6948B324EF3E88C7435198F7E6648FF279229A15E75C37
sha3_384: 1bff7df4828d237eef9099f6b6dda97939af10f0557391751732009db6a24918414b1c7e69e641880d006079924fbf45
ep_bytes: 5589e5575683e4f889e6a148ac4500b9
timestamp: 2024-01-19 20:39:14

Version Info:

0: [No Data]

Trojan:Win32/LummaStealer.CADV!MTB also known as:

BkavW32.Common.AD7ACD16
LionicTrojan.Win32.LummaStealer.a!c
AVGWin32:SpywareX-gen [Trj]
ElasticWindows.Generic.Threat
MicroWorld-eScanGen:Variant.Lazy.449542
FireEyeGeneric.mg.2f7b5b7eba431145
SkyhighBehavesLike.Win32.Generic.hc
McAfeeArtemis!2F7B5B7EBA43
MalwarebytesTrojan.Downloader
ZillyaTrojan.Agent.Win32.3870444
SangforSpyware.Win32.Lummastealer.Vwrh
K7AntiVirusSpyware ( 005af7031 )
AlibabaTrojanDownloader:Win32/LummaStealer.28089082
K7GWSpyware ( 005af7031 )
BitDefenderThetaAI:Packer.A22EA8D71E
VirITTrojan.Win32.Genus.UZD
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.QLD
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Infostealer.Lumma-10027222-0
KasperskyHEUR:Trojan-Downloader.Win32.Zload.gen
BitDefenderGen:Variant.Lazy.449542
NANO-AntivirusTrojan.Win32.Zload.kkplnu
AvastWin32:SpywareX-gen [Trj]
RisingSpyware.Agent!8.C6 (TFE:3:mKdp3jyi9oN)
EmsisoftGen:Variant.Lazy.449542 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PWS.Lumma.93
VIPREGen:Variant.Lazy.449542
TrendMicroTrojanSpy.Win32.LUMMASTEALER.YXECOZ
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
VaristW32/Agent.ICN.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Downloader]/Win32.Zload
KingsoftWin32.Trojan-Downloader.Zload.gen
MicrosoftTrojan:Win32/LummaStealer.CADV!MTB
ArcabitTrojan.Lazy.D6DC06
ViRobotTrojan.Win.Z.Agent.523280
ZoneAlarmHEUR:Trojan-Downloader.Win32.Zload.gen
GDataGen:Variant.Lazy.449542
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5578021
VBA32TrojanPSW.Lumma
ALYacGen:Variant.Lazy.449542
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.LUMMASTEALER.YXECOZ
TencentMalware.Win32.Gencirc.11bd8f55
YandexTrojanSpy.Agent!L3VK0SZkmh4
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Malware.82357917.susgen
FortinetW32/Agent.QLD!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/LummaStealer.CADV!MTB

How to remove Trojan:Win32/LummaStealer.CADV!MTB?

Trojan:Win32/LummaStealer.CADV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment