Trojan

UDS:Trojan.Win32.Selfmod removal tips

Malware Removal

The UDS:Trojan.Win32.Selfmod is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Selfmod virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine UDS:Trojan.Win32.Selfmod?


File Info:

name: 89966A7F93DD724AE10F.mlw
path: /opt/CAPEv2/storage/binaries/70e875e3906ebb9b9093fcf1bfbea9d779b6e93eeebb770027972d41e5492553
crc32: 1AD3486C
md5: 89966a7f93dd724ae10f1ce7a1308947
sha1: 29bdecee37c8652d264fc8e4cebf9c729c0005e9
sha256: 70e875e3906ebb9b9093fcf1bfbea9d779b6e93eeebb770027972d41e5492553
sha512: 4c5dc08ca072104a5290db18c6d0a3a78bd34ea45048e06336e43047f8be3fdcc988d7be314c1955f01b76120abd98bcdd765d3152e57007fb984c3b87768adf
ssdeep: 49152:qKqnStm3L8/lr2Marga6qM+gS6ga6qM+g:hq0w/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T175F57E193F715443C7C5F239B9EA9E204C116C2C7A36E22E74C7757E7922E8CE58A62C
sha3_384: 05364ad131ed07f255400b67aa094e98eb287d45795b83be64a6a4dbedc1e7d95ad736d3d748337b0026b0f9dfb7d6eb
ep_bytes: 80d8f697d0b17210d5507b81571a133b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

UDS:Trojan.Win32.Selfmod also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.773164
FireEyeGeneric.mg.89966a7f93dd724a
CAT-QuickHealTrojan.Glupteba.S16915173
ALYacGen:Variant.Razy.773164
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005766931 )
K7GWTrojan ( 005766931 )
Cybereasonmalicious.f93dd7
BitDefenderThetaGen:NN.ZexaF.34294.CJZ@a8lvKEl
CyrenW32/Zusy.EM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIFY
ClamAVWin.Packed.Dridex-9860931-1
KasperskyUDS:Trojan.Win32.Selfmod.gen
BitDefenderGen:Variant.Razy.773164
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Razy.773164
ComodoTrojWare.Win32.Kryptik.TLS@812zm8
ZillyaTrojan.Kryptik.Win32.2605434
McAfee-GW-EditionBehavesLike.Win32.Sivis.wh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.773164 (B)
APEXMalicious
GDataWin32.Trojan.PSE.1T8KH4S
AviraHEUR/AGEN.1139880
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C549
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Packed.R357221
Acronissuspicious
McAfeePacked-FJB!89966A7F93DD
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Glupteba
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove UDS:Trojan.Win32.Selfmod?

UDS:Trojan.Win32.Selfmod removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment