Spy Trojan

UDS:Trojan-Spy.Win32.Stealer.cdww removal instruction

Malware Removal

The UDS:Trojan-Spy.Win32.Stealer.cdww is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Stealer.cdww virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • A process created a hidden window
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine UDS:Trojan-Spy.Win32.Stealer.cdww?


File Info:

name: 9012CF7B4BF386DBA7AC.mlw
path: /opt/CAPEv2/storage/binaries/3e6ece8352fba89ba04018370010b03c074eab96a98e279ff25ad66b8a2e0ff0
crc32: 717207E6
md5: 9012cf7b4bf386dba7ac32119f0bad12
sha1: f6c5edce3f4e78f2b78408dcfedadee3e6ee31a5
sha256: 3e6ece8352fba89ba04018370010b03c074eab96a98e279ff25ad66b8a2e0ff0
sha512: b500725f8b5686da23a37eee98430cc94f0cf160ab1f162894d92deec7865b180a0d72e97beb07d0864186121fe1da5a834cec24f760deb0d9e6a4272ca5eb35
ssdeep: 49152:qZ7+8YkHlDMYg5JYTd+PHMdrwYV/YY4uLSTSCbB96NF6E7qw:qZ72kHlDMYg5JYTd+PHMdrwY2jkzn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB953A68EB4754F1EA2356B0814FEB7F8B247D15C021EEBBFF8ADE06B4335122819255
sha3_384: 72c51cdf01631d685cefb881bdd8db8fb247647246814ae3bc1c8e8a92fd77d469b1172514e32a04a3bd0d1534d6d2a3
ep_bytes: c705b0c15b0001000000e9b1fcffff90
timestamp: 2022-07-06 19:29:42

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Stealer.cdww also known as:

LionicTrojan.Win32.Stealer.l!c
MicroWorld-eScanTrojan.GenericKD.49320761
FireEyeGeneric.mg.9012cf7b4bf386db
ALYacTrojan.GenericKD.49320761
VIPRETrojan.GenericKD.49320761
BitDefenderThetaGen:NN.ZexaF.34786.1PX@ae0WtYfi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCGGZ
KasperskyUDS:Trojan-Spy.Win32.Stealer.cdww
BitDefenderTrojan.GenericKD.49320761
AvastWin32:MalOb-IJ [Cryp]
Ad-AwareTrojan.GenericKD.49320761
SophosGeneric Reputation PUA (PUA)
TrendMicroTrojanSpy.Win32.REDLINE.YXCGGZ
McAfee-GW-EditionBehavesLike.Win32.Injector.th
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.49320761 (B)
GDataTrojan.GenericKD.49320761
AviraTR/Spy.Gen
MAXmalware (ai score=84)
ArcabitTrojan.Generic.D2F09339
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C5197752
McAfeeArtemis!9012CF7B4BF3
RisingStealer.Agent!8.C2 (CLOUD)
FortinetW32/PossibleThreat
AVGWin32:MalOb-IJ [Cryp]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove UDS:Trojan-Spy.Win32.Stealer.cdww?

UDS:Trojan-Spy.Win32.Stealer.cdww removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment