Trojan

UDS:Trojan-PSW.Win32.Stealer.xap removal

Malware Removal

The UDS:Trojan-PSW.Win32.Stealer.xap is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-PSW.Win32.Stealer.xap virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Creates a hidden or system file
  • CAPE detected the A310Logger malware family
  • Anomalous binary characteristics

How to determine UDS:Trojan-PSW.Win32.Stealer.xap?


File Info:

name: B35D7360CEB388C3912C.mlw
path: /opt/CAPEv2/storage/binaries/a623df3340c96e244971970bd22bdd9bee702607b4406539171f67b5b079e4a0
crc32: 982219AC
md5: b35d7360ceb388c3912cf4a5beb3c489
sha1: 8f0e50b2f02397f0fdbd2ab1b16d6ae90ea74425
sha256: a623df3340c96e244971970bd22bdd9bee702607b4406539171f67b5b079e4a0
sha512: 7ee0b9abdcc5d3c8ca7b9b8212e798899f1d0c70176a2b1f8a80d649ecd143c243252ad170d6f970556c6677d44f9b4f5812b4e30582d2c0e00c7c768f9364c4
ssdeep: 98304:Wmg7KD4ruJINy/JX7ZGg1GJnz5cZtDHtc2yXoqCia5xdD/WEFW6Ybr:zOw7WshczdNcZtDHC2WoqCNrDL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1127633775EF61802FA2A50BF4B9DC22A890C5C8A3166BF11BA1B1D41505FCC89D8F67F
sha3_384: 452cb682cea4178078b743d4e68ff1d2c45349c924804c0adc70217702be0ed8cc0c5c0518765d55a2ee2cbc3cb5dd5a
ep_bytes: e8c1cf6e006a00ff15a400af00c3d4a5
timestamp: 2021-11-28 13:59:25

Version Info:

0: [No Data]

UDS:Trojan-PSW.Win32.Stealer.xap also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.931651
FireEyeGeneric.mg.b35d7360ceb388c3
ALYacGen:Variant.Razy.931651
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34294.@pW@a0GEj4b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FKNU
Paloaltogeneric.ml
KasperskyUDS:Trojan-PSW.Win32.Stealer.xap
BitDefenderGen:Variant.Razy.931651
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Razy.931651
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.931651 (B)
IkarusTrojan.Win32.Krypt
AviraHEUR/AGEN.1119113
MicrosoftVirTool:Win32/Pucrpt.A!MTB
GDataGen:Variant.Razy.931651
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R442079
Acronissuspicious
McAfeeGenericRXQG-GX!B35D7360CEB3
VBA32BScope.Trojan.Wacatac
MalwarebytesBackdoor.AsyncRAT
APEXMalicious
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Emotet.5C62!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.0ceb38
PandaTrj/Genetic.gen

How to remove UDS:Trojan-PSW.Win32.Stealer.xap?

UDS:Trojan-PSW.Win32.Stealer.xap removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment