Spy

Generic.PySpy.A.70C71538 information

Malware Removal

The Generic.PySpy.A.70C71538 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PySpy.A.70C71538 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PySpy.A.70C71538?


File Info:

name: 7E4F2D5F060AB66B651D.mlw
path: /opt/CAPEv2/storage/binaries/9c78edb817194eab440ac49877211988b015e41b27850d62f202de87777c05cc
crc32: D4966DE6
md5: 7e4f2d5f060ab66b651d4af6981faf4e
sha1: dfea1fa015f49c3ba5e12e46001df68c6a9e6ff5
sha256: 9c78edb817194eab440ac49877211988b015e41b27850d62f202de87777c05cc
sha512: 2666061a6377fefdec60856dd5d3897930fe31a84a4183392407a4721e3528915ba939bdbd33fccf81801202f56fe1d6a1a331ead39e815834e2618dcd70a530
ssdeep: 98304:PYilXpzoLLJ3TbwaVvrZE0Idx1kgCPOGCWxMa7kC9dobZx8mSUNPqjtCp1FUQo:PYm9onJ5hrZERPktPOKjPobZx5wFv
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1C266330E716154E8F5F9943645801838DA73B83A4722D71F5B6C13AAAFB39E1AD3DF02
sha3_384: d763f89a087ccf914ae501fe44443386fbc99d01c6e0f9b00d0b026f36b9a6cb2d4a65ce182071cde250813f5e70dfe8
ep_bytes: 4883ec28e84f0500004883c428e982fe
timestamp: 2021-01-13 09:45:33

Version Info:

0: [No Data]

Generic.PySpy.A.70C71538 also known as:

Elasticmalicious (high confidence)
DrWebPython.Stealer.175
MicroWorld-eScanGeneric.PySpy.A.70C71538
FireEyeGeneric.PySpy.A.70C71538
ALYacGeneric.PySpy.A.70C71538
CylanceUnsafe
K7AntiVirusTrojan ( 00568ccf1 )
AlibabaTrojanPSW:Win32/Almi_Disco.e
CyrenPYC/Disgrab.B.gen!Camelot
SymantecTrojan.Gen.MBT
ESET-NOD32Python/PSW.Agent.BP
TrendMicro-HouseCallTROJ_GEN.R002C0PL421
Paloaltogeneric.ml
KasperskyUDS:Trojan-PSW.Win64.Disco.gen
BitDefenderGeneric.PySpy.A.70C71538
AvastPython:PWStealer-A [Spy]
Ad-AwareGeneric.PySpy.A.70C71538
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PL421
McAfee-GW-EditionBehavesLike.Win64.Generic.vc
SentinelOneStatic AI – Suspicious PE
EmsisoftGeneric.PySpy.A.70C71538 (B)
AviraHEUR/AGEN.1202352
GridinsoftRansom.Win64.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan-Stealer.Cordimik.Q4MFLH
CynetMalicious (score: 100)
McAfeeArtemis!7E4F2D5F060A
APEXMalicious
TencentWin32.Trojan-psw.Agent.Ajmd
MAXmalware (ai score=85)
FortinetPython/Agent.BP!tr
AVGPython:PWStealer-A [Spy]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.PySpy.A.70C71538?

Generic.PySpy.A.70C71538 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment