Spy Trojan

About “UDS:Trojan-Spy.Win32.Stealer.cmse” infection

Malware Removal

The UDS:Trojan-Spy.Win32.Stealer.cmse is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Stealer.cmse virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine UDS:Trojan-Spy.Win32.Stealer.cmse?


File Info:

name: 8276CA8824D4BDA1EDF0.mlw
path: /opt/CAPEv2/storage/binaries/ca5bca37a0799bc42be75de72641ced73bbe8f41d81f7827e462a7bc96b9d132
crc32: 9534630F
md5: 8276ca8824d4bda1edf0c7e52afc4121
sha1: 78cba2bd54cd9d94c26ba60793c3e0a88e762c93
sha256: ca5bca37a0799bc42be75de72641ced73bbe8f41d81f7827e462a7bc96b9d132
sha512: d04dbb628efb74cb44e2248857059b22f51c6864c58932e8fa9ebe78ceb292340634a840db5fba4dfde01e075d8161a466bfc269e6c6fe83aafbd2c494ff04a0
ssdeep: 24576:kC7OYKYM8f1kCMoCoXDrZ5ihesIsVzNPZAgeISqaxLH+QYGl3RuQ55313Z:kCXJW7VZCgeISqax7+4l3/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19EC509036ACB1E75DDC23BB4618B533BA734ED30CA2A9B7FBA08C53559532D46C1A742
sha3_384: c5cdb84aff14137bcc78fffa714425160069a2414104f44736efb0b22390493c536f032ea2630961680790acc1269146
ep_bytes: 83ec0cc705b863510000000000e83e8b
timestamp: 2022-08-31 08:42:38

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Stealer.cmse also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fragtor.136511
FireEyeGen:Variant.Fragtor.136511
ALYacGen:Variant.Babar.97945
CylanceUnsafe
ArcabitTrojan.Babar.D17E99
BitDefenderThetaGen:NN.ZexaF.34606.z!Z@a8V6g7n
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQPJ
ClamAVWin.Packed.Generic-9966162-0
KasperskyUDS:Trojan-Spy.Win32.Stealer.cmse
BitDefenderGen:Variant.Fragtor.136511
CynetMalicious (score: 100)
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Fragtor.136511
EmsisoftGen:Variant.Fragtor.136511 (B)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1M3Z1WV
GoogleDetected
MAXmalware (ai score=83)
VBA32Trojan.MSIL.InfoStealer.gen.U
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!8.8 (TFE:5:qFgFsCC2vGK)
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Trojan-gen

How to remove UDS:Trojan-Spy.Win32.Stealer.cmse?

UDS:Trojan-Spy.Win32.Stealer.cmse removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment