Spy

What is “Generic.PySpy.A.1B98095B”?

Malware Removal

The Generic.PySpy.A.1B98095B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PySpy.A.1B98095B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PySpy.A.1B98095B?


File Info:

name: 55CEF29F06F3C6044EA0.mlw
path: /opt/CAPEv2/storage/binaries/1d93981afb36e5cf94a393baf87b2fe760658d5b6a2e83145f46800c5dee9167
crc32: C636C07D
md5: 55cef29f06f3c6044ea0704f3654aeb2
sha1: 1abda05209ea478cdea2b5de20d349c251cadad2
sha256: 1d93981afb36e5cf94a393baf87b2fe760658d5b6a2e83145f46800c5dee9167
sha512: 7800b74eecfe81ae5bf04154f69a94f2d56dcfb007e58b08990c44711682c7840d54b75b8a980d5d0cbbcadca900ad1be666d031be7f668ce79dd7e2306b1190
ssdeep: 196608:2iSfQICteEroXx7IP0oTcMsABqlNypH3fq46AQ:eQInEroXOMogFABqDIH3C4t
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1CB663347B66C0DE7E9A6B13489430121D432BC794BB3DD4B33D8B5660FB76B06E66E80
sha3_384: e5d056a102d557827fea132ee4216411b100ea696d3b8effc2bc0e5df2973d4186aa4df94610f0d3cc2ad503d9f986e1
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-11-09 18:03:59

Version Info:

0: [No Data]

Generic.PySpy.A.1B98095B also known as:

LionicTrojan.Win64.Disco.i!c
Elasticmalicious (high confidence)
DrWebPython.Stealer.194
MicroWorld-eScanGeneric.PySpy.A.1B98095B
FireEyeGeneric.PySpy.A.1B98095B
McAfeeArtemis!55CEF29F06F3
CylanceUnsafe
ZillyaTrojan.Agent.Script.1642598
K7AntiVirusTrojan ( 00568ccf1 )
AlibabaTrojanPSW:Win32/Almi_Disco.e
K7GWTrojan ( 00568ccf1 )
CyrenPYC/Disgrab.B.gen!Camelot
SymantecTrojan.Gen.MBT
ESET-NOD32Python/PSW.Agent.BP
TrendMicro-HouseCallTROJ_GEN.R002H0CL721
Paloaltogeneric.ml
ClamAVWin.Malware.Tedy-9918274-0
KasperskyUDS:Trojan-PSW.Win64.Disco.gen
BitDefenderGeneric.PySpy.A.1B98095B
AvastPython:PWStealer-A [Spy]
Ad-AwareGeneric.PySpy.A.1B98095B
EmsisoftGeneric.PySpy.A.1B98095B (B)
McAfee-GW-EditionBehavesLike.Win64.Ransom.vc
SophosMal/Generic-S
IkarusTrojan-Spy.Python.Disgrab
GDataGeneric.PySpy.A.1B98095B
JiangminTrojan.Agentb.kqi
AviraTR/PSW.Agent.csxeg
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34CE845
GridinsoftRansom.Win64.Sabsik.sa
ArcabitGeneric.PySpy.A.1B98095B
MicrosoftTrojan:Win32/Mamson.A!ac
CynetMalicious (score: 100)
VBA32TrojanPSW.Win64.Disco
ALYacGeneric.PySpy.A.1B98095B
TencentWin32.Trojan-psw.Agent.Sxfa
FortinetPython/Agent.BP!tr
AVGPython:PWStealer-A [Spy]
MaxSecureTrojan.Malware.117608885.susgen

How to remove Generic.PySpy.A.1B98095B?

Generic.PySpy.A.1B98095B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment