Spy Trojan

UDS:Trojan-Spy.Win32.Stealer.cgyb removal tips

Malware Removal

The UDS:Trojan-Spy.Win32.Stealer.cgyb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Stealer.cgyb virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine UDS:Trojan-Spy.Win32.Stealer.cgyb?


File Info:

name: BAC2C024000CFC76A7E9.mlw
path: /opt/CAPEv2/storage/binaries/58117f0d2c7e660e88b094fc84eca86b9c27db6b40a38dc3ea20b0cb8320cc6e
crc32: D20CA65D
md5: bac2c024000cfc76a7e90bc4e692c9c3
sha1: 48441897d5af6920e9791ddde09214c8d5752d9e
sha256: 58117f0d2c7e660e88b094fc84eca86b9c27db6b40a38dc3ea20b0cb8320cc6e
sha512: fefdb6ded820a450a5a4e1c5efbdd214191ccba2f2155c490f01a999044739d9ffaf2c69b965c6f4eabad3a8640943e604cd664d2c56ba86e18a94b4bd29763c
ssdeep: 24576:wx03zoD19M+YmYwP/rrG28M6ldQCPetYWW/aFmY1xrNo88L0w1qe41Rarl3RuQ5v:wOjS19xg9jI1xrNo88iKl39
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T115C51A135A8B0E75DDD23BB4A1CB633EA734ED30CA3A9B7BB608C53559532C46C1A742
sha3_384: 14b422d65e45adceb9c174f507ab3a0b2de22095a0adb7ed8154a47480280fb10a12bb0dffbc582d0bd3fe99602262cb
ep_bytes: 83ec0cc705b823520000000000e89e03
timestamp: 2022-07-22 22:19:57

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Stealer.cgyb also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.90061
McAfeeGenericRXTS-CW!BAC2C024000C
CylanceUnsafe
VIPRETrojan.GenericKDZ.90061
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQDK
KasperskyUDS:Trojan-Spy.Win32.Stealer.cgyb
BitDefenderTrojan.GenericKDZ.90061
TencentTrojan.Win32.Kryptik.zaa
Ad-AwareTrojan.GenericKDZ.90061
EmsisoftTrojan.GenericKDZ.90061 (B)
FireEyeTrojan.GenericKDZ.90061
SophosTroj/Steal-CVF
IkarusTrojan.Win32.Krypt
GDataWin32.Trojan.PSE.1SVY8VM
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D15FCD
ZoneAlarmUDS:Trojan-Spy.Win32.Stealer.cgyb
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.AntiAV.R506128
BitDefenderThetaGen:NN.ZexaF.34806.E!Z@aO1DxPe
ALYacTrojan.GenericKDZ.90061
VBA32BScope.TrojanPSW.Arkei
MalwarebytesSpyware.PasswordStealer
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgU5pikKdNIj0A)
FortinetW32/Kryptik.HQDK!tr

How to remove UDS:Trojan-Spy.Win32.Stealer.cgyb?

UDS:Trojan-Spy.Win32.Stealer.cgyb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment