Trojan

UDS:Trojan-PSW.Win32.Stealer.wss removal instruction

Malware Removal

The UDS:Trojan-PSW.Win32.Stealer.wss is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-PSW.Win32.Stealer.wss virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients

How to determine UDS:Trojan-PSW.Win32.Stealer.wss?


File Info:

name: CCE02BA989E91C0E41DF.mlw
path: /opt/CAPEv2/storage/binaries/d8d92da01936da576df485be516c193b861bd741c83a41b6cc437758a57a01b3
crc32: 9014043B
md5: cce02ba989e91c0e41df2cb3ed6409eb
sha1: e236405985d7c0b7957b2a7f0c17084735b3fd31
sha256: d8d92da01936da576df485be516c193b861bd741c83a41b6cc437758a57a01b3
sha512: eeee45317e41556b31a43c69e1a1757571a7685d6b2621c299adb1cec7eec0663937b319c33428966851055e4e4de578ae7375865368f850cc86403fcabfb89f
ssdeep: 24576:q4lavt0LkLL9IMixoEgeaKFpSUFXqSBlMmM1d5lbW2UdvZQ6IXMTxNjPmz008q9/:9kwkn9IMHeaKFp7RBlwtbZUzQ/XMTx5e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18375E00373ED83A5C3729233BA16BB51AEBB7C250671F59B1FD5093DAD20121422EA73
sha3_384: 2aea84ce534de09df39117ae62b7aa15b1da239ac7cb219f3732ca3755d062a35a6d72c3ab819d118aeb145f908d4403
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2021-11-22 22:27:08

Version Info:

Translation: 0x0809 0x04b0

UDS:Trojan-PSW.Win32.Stealer.wss also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4778
FireEyeGeneric.mg.cce02ba989e91c0e
McAfeeArtemis!CCE02BA989E9
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
ArcabitAIT:Trojan.Nymeria.D12AA
CyrenW32/AutoIt.SM.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/PSWTool.MailPassView.E potentially unsafe
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Trojan-PSW.Win32.Stealer.wss
BitDefenderAIT:Trojan.Nymeria.4778
AvastFileRepMetagen [Malware]
Ad-AwareAIT:Trojan.Nymeria.4778
SophosGeneric ML PUA (PUA)
F-SecureDropper.DR/AutoIt.Gen8
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftAIT:Trojan.Nymeria.4778 (B)
AviraDR/AutoIt.Gen8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataAIT:Trojan.Nymeria.4778 (2x)
AhnLab-V3Malware/Win32.Generic.C4192480
ALYacAIT:Trojan.Nymeria.4778
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3616357514
eGambitUnsafe.AI_Score_96%
FortinetAutoIt/Agent.OZU!tr
AVGFileRepMetagen [Malware]
MaxSecureTrojan.Malware.300983.susgen

How to remove UDS:Trojan-PSW.Win32.Stealer.wss?

UDS:Trojan-PSW.Win32.Stealer.wss removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment