Spy

Dropped:Generic.PySpy.B.CADC38D3 removal guide

Malware Removal

The Dropped:Generic.PySpy.B.CADC38D3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.PySpy.B.CADC38D3 virus can do?

  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Attempts to execute suspicious powershell command arguments
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropped:Generic.PySpy.B.CADC38D3?


File Info:

name: 836D4245261811AC4BF4.mlw
path: /opt/CAPEv2/storage/binaries/a047381058143b41a7d71f015d26bdda4f74d6e4f826a995d4d14fe38b49032a
crc32: 73FCD808
md5: 836d4245261811ac4bf4aec2e6fc04de
sha1: 5e06170bc10ef176052584e1d5495490eab20036
sha256: a047381058143b41a7d71f015d26bdda4f74d6e4f826a995d4d14fe38b49032a
sha512: 6b807281a96837a172074874db7f15c8b511a70e62f71812840f066ca742ece82637fff6298315e707d1d9a4c8ecb3781a3e3308674fb445b0a6d359a70aad87
ssdeep: 1536:opfEKNCj6VoJl9Go5K7s4Nu3Oz0Xxl6F4sDObW8jKX7nouy8ZOu:oVZ/VGS7rN+OgXxle4sibAoutX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16843F107D9889457E6A460785C0F1C787EECD7B437C083A2FCC023768EA1B424B1A72E
sha3_384: 3e0a0812feeef0121a13c5b6aa97a517f4d4f8d3601a11cc571c01724c995f63fcc0c87b9f47079fb44d5b2bf4d0a860
ep_bytes: 60be151041008dbeebfffeff5789e58d
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Dropped:Generic.PySpy.B.CADC38D3 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Generic.PySpy.B.CADC38D3
FireEyeGeneric.mg.836d4245261811ac
McAfeeArtemis!836D42452618
MalwarebytesMalware.AI.1162554859
VIPREDropped:Generic.PySpy.B.CADC38D3
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0051918e1 )
AlibabaTrojanSpy:Win32/Generic.137aaa7a
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.526181
CyrenW32/ABSpyware.KEJK-7151
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.PowerShell.Agent.gen
BitDefenderDropped:Generic.PySpy.B.CADC38D3
AvastWin32:Malware-gen
TencentWin32.Trojan-Spy.Agent.Cflw
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.irxxw
TrendMicroTROJ_GEN.R011C0PF223
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
EmsisoftDropped:Generic.PySpy.B.CADC38D3 (B)
IkarusTrojan.Win32.KillDisk
GDataDropped:Generic.PySpy.B.CADC38D3
AviraTR/Redcap.irxxw
Antiy-AVLTrojan/Win32.Tiggre
ArcabitGeneric.PySpy.B.CADC38D3
ZoneAlarmHEUR:Trojan-Spy.PowerShell.Agent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
ALYacDropped:Generic.PySpy.B.CADC38D3
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R011C0PF223
RisingSpyware.Agent/PS!8.1361C (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Dropped:Generic.PySpy.B.CADC38D3?

Dropped:Generic.PySpy.B.CADC38D3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment