Spy

What is “Generic.PySpy.A.5B8D75AC”?

Malware Removal

The Generic.PySpy.A.5B8D75AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PySpy.A.5B8D75AC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PySpy.A.5B8D75AC?


File Info:

name: 3588D82183E383C31CDB.mlw
path: /opt/CAPEv2/storage/binaries/66e75581590dc8c740ca6851a293b90a433041b5470cdf6516fe931a593c8b96
crc32: 89AD47B9
md5: 3588d82183e383c31cdb5dc394e697c9
sha1: 0a3b9aa8e1234d4808b2d03d36b07f2f7621ef4e
sha256: 66e75581590dc8c740ca6851a293b90a433041b5470cdf6516fe931a593c8b96
sha512: 903652fe9220c98888db1c61be1838d4b17a66d63629e17ed446ccb17c4bc96e9083d42ab5068e0f0cc1b2bfec28fc95a4c8b555a9d60169d39884ffef409970
ssdeep: 196608:u2WHru9xrDpFC4g0AVIGv38ZJ9BIBxIFWacuKp+qQ9/M:uS9xrLgtIGiYXIRKp+l90
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1717633122B525CC0C17941368DA4CD35A272BC072B35972B1BDC2F67FE767E2AD3AA50
sha3_384: 53ee4f97e318eeeb16d7ab5ca7660f343a682bdb9b55940b1022985f11a16121ba80d173bf443bc4d249e9090352cdc8
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-04-15 05:29:45

Version Info:

0: [No Data]

Generic.PySpy.A.5B8D75AC also known as:

DrWebPython.Stealer.194
MicroWorld-eScanGeneric.PySpy.A.5B8D75AC
FireEyeGeneric.mg.3588d82183e383c3
McAfeeArtemis!3588D82183E3
CylanceUnsafe
K7AntiVirusTrojan ( 00568ccf1 )
AlibabaTrojanPSW:Win32/Almi_Disco.e
K7GWTrojan ( 00568ccf1 )
CyrenPYC/Disgrab.B.gen!Camelot
SymantecTrojan.Gen.MBT
ESET-NOD32Python/PSW.Agent.BP
TrendMicro-HouseCallTROJ_GEN.R002C0PL321
Paloaltogeneric.ml
KasperskyUDS:Trojan-PSW.Win64.Disco.gen
BitDefenderGeneric.PySpy.A.5B8D75AC
AvastPython:PWStealer-A [Spy]
TencentWin32.Trojan-psw.Agent.Ljue
Ad-AwareGeneric.PySpy.A.5B8D75AC
EmsisoftGeneric.PySpy.A.5B8D75AC (B)
TrendMicroTROJ_GEN.R002C0PL321
McAfee-GW-EditionBehavesLike.Win64.Trojan.wc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraTR/PSW.Agent.ubmkc
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.329AD80
GridinsoftRansom.Win64.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGeneric.PySpy.A.5B8D75AC
CynetMalicious (score: 100)
VBA32TrojanPSW.Win64.Disco
ALYacGeneric.PySpy.A.5B8D75AC
IkarusTrojan-Spy.Python.Disgrab
FortinetPython/Agent.BP!tr
AVGPython:PWStealer-A [Spy]

How to remove Generic.PySpy.A.5B8D75AC?

Generic.PySpy.A.5B8D75AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment