Spy

Generic.PySpy.A.B5E1B860 removal instruction

Malware Removal

The Generic.PySpy.A.B5E1B860 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PySpy.A.B5E1B860 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PySpy.A.B5E1B860?


File Info:

name: 2D0B56692EFDEEDD1944.mlw
path: /opt/CAPEv2/storage/binaries/0804c9931c3b19bd027034a80f699f83c77df425d042ebf5605cf16e3b25d278
crc32: ED30883C
md5: 2d0b56692efdeedd1944aaf77474edfe
sha1: eb7d43d201e41ff28d9b00be83bcb023965c22c5
sha256: 0804c9931c3b19bd027034a80f699f83c77df425d042ebf5605cf16e3b25d278
sha512: 52fda7162cd874fdbe3f6b35e6375ba65b60bcdcd57a6a3c3418ba190dd30ce63e3658b0b19373927cb91191d22f37cc780b0806a8b2175565e05eab09aa1b4c
ssdeep: 196608:Ukg+hvICteEroXxqENE+sKsXXgvke0AwkedmBNqr:FInEroXjsKkXgse0tON8
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1B466330062F408EEF8BB8638C5A5C234A472B82B9755D59F13EC8B9B6F535C32E77644
sha3_384: 2a37d99f4319b02c2f82e461e9ae672ba188232ed1501f9dd422497f9bcd180a5312cda1bf5474d54fc403a6fbac1d42
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-11-09 18:03:59

Version Info:

0: [No Data]

Generic.PySpy.A.B5E1B860 also known as:

LionicTrojan.Win64.Disco.i!c
DrWebPython.Stealer.194
MicroWorld-eScanTrojan.GenericKD.38263842
McAfeeArtemis!2D0B56692EFD
CylanceUnsafe
ZillyaTrojan.Agent.Script.1642598
AlibabaTrojanPSW:Win32/Almi_Disco.e
SymantecTrojan.Gen.MBT
ESET-NOD32Python/PSW.Agent.BP
TrendMicro-HouseCallTROJ_GEN.R002H0CLB21
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.38263842
AvastPython:PWStealer-A [Spy]
Ad-AwareTrojan.GenericKD.38263842
McAfee-GW-EditionBehavesLike.Win64.Ransom.vc
FireEyeTrojan.GenericKD.38263842
EmsisoftTrojan.GenericKD.38263842 (B)
IkarusTrojan-Spy.Python.Disgrab
GDataTrojan.GenericKD.38263842
JiangminTrojan.Agentb.kqi
AviraTR/PSW.Agent.gfdhq
Antiy-AVLTrojan/Generic.ASMalwS.34CE845
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D247DC22
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGeneric.PySpy.A.B5E1B860
MAXmalware (ai score=88)
MalwarebytesSpyware.DiscordStealer.Python
TencentWin32.Trojan-psw.Agent.Hqvr
FortinetPython/Agent.BP!tr
AVGPython:PWStealer-A [Spy]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.PySpy.A.B5E1B860?

Generic.PySpy.A.B5E1B860 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment