Malware

Generic.PY.Discorder.A.FE3EAF90 removal guide

Malware Removal

The Generic.PY.Discorder.A.FE3EAF90 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PY.Discorder.A.FE3EAF90 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PY.Discorder.A.FE3EAF90?


File Info:

name: 30DB98BA8AF7426F493B.mlw
path: /opt/CAPEv2/storage/binaries/e92cce87bd0f385fb5fe061cd42dbe04892354d487e2d654b895af1a8017fcaa
crc32: 8D9A3653
md5: 30db98ba8af7426f493bf59fbda6f4ea
sha1: e134e32e145e2ba97403f7241f8018a3aa8b6e11
sha256: e92cce87bd0f385fb5fe061cd42dbe04892354d487e2d654b895af1a8017fcaa
sha512: dcad07a5797c195c71065533ce1c0b0133b58f5174491dda21fb2a375b835703e5f0682f9bf361c7613bb13b76cefb3eacfe9f76fa4c462e090d16e6d2d6b797
ssdeep: 98304:awlh9zAxOcYVH917pxXtVd1bXGF67DQKLjiRck3z4CNga18Nv8H8E6zloDkAohTF:fAxOcEPlxXb7NmH3zXgi8Nk6JoDhUTl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7363361B8C480A3E47A1C3148B8C7BA2C6EE6255760894FEBC58F797D307D0E1BA65D
sha3_384: 963a8dfd989c75efeb6622b75e8f641b0f16dd39a3c4e17b64223e6bebdf541a94f0158c8eb032729640caecf56ea52e
ep_bytes: e8a0040000e978feffff558bec6a00ff
timestamp: 2022-07-14 22:51:14

Version Info:

0: [No Data]

Generic.PY.Discorder.A.FE3EAF90 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.30db98ba8af7426f
McAfeePython/PWS.p
ZillyaTrojan.Agent.Script.1714622
BitDefenderGeneric.PY.Discorder.A.FE3EAF90
ArcabitGeneric.PY.Discorder.A.FE3EAF90
ESET-NOD32Python/PSW.Agent.GL
APEXMalicious
KasperskyHEUR:Trojan-PSW.Multi.Disco.gen
MicroWorld-eScanGeneric.PY.Discorder.A.FE3EAF90
Ad-AwareGeneric.PY.Discorder.A.FE3EAF90
EmsisoftGeneric.PY.Discorder.A.FE3EAF90 (B)
DrWebPython.Stealer.454
VIPREGeneric.PY.Discorder.A.FE3EAF90
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosGeneric ML PUA (PUA)
JiangminTrojanSpy.Python.ao
Antiy-AVLTrojan/Generic.ASMalwS.7780
MicrosoftTrojan:Win32/Sabsik.FT.A!ml
ZoneAlarmHEUR:Trojan-PSW.Multi.Disco.gen
GDataGeneric.PY.Discorder.A.FE3EAF90
ALYacGeneric.PY.Discorder.A.FE3EAF90
MAXmalware (ai score=86)
RisingStealer.Discord!1.DBAF (CLASSIC)
IkarusTrojan-Spy.Python.Disgrab
FortinetPython/Agent.EX!tr
AVGMulti:Agent-AI [Trj]
AvastMulti:Agent-AI [Trj]

How to remove Generic.PY.Discorder.A.FE3EAF90?

Generic.PY.Discorder.A.FE3EAF90 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment