Spy

Generic.PySpy.A.F3B868AB information

Malware Removal

The Generic.PySpy.A.F3B868AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PySpy.A.F3B868AB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PySpy.A.F3B868AB?


File Info:

name: 52DC3E1BD6E81937BF1C.mlw
path: /opt/CAPEv2/storage/binaries/556ff7eac1684bbbf4a5e6289f23f81fc5ac3e0837703aab0ec03c9f70f94def
crc32: 948685F2
md5: 52dc3e1bd6e81937bf1c83da8e3109b8
sha1: 202c91a0c004fb43d9a92fea5f4618bc5f9c6d59
sha256: 556ff7eac1684bbbf4a5e6289f23f81fc5ac3e0837703aab0ec03c9f70f94def
sha512: 6c239a79a67d879c8e50d10fe5b85013f9fb99a8ee4bf4f73c3d8c9e97b8e411df85abd7bc14ec6f7ae61409ab42c59bd149b518f3d05fd974e6d3e4d5c48931
ssdeep: 196608:9sEbGXVFICteEroXxoczlxZV3Gu5D4S26/CS31V6T8B9I1HJ:SEeInEroXF14S26VV6sA
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T111663330AEA818E9D6E68075846CCD6FB1B26F504343D1DA1768BC264F736A37DE7B04
sha3_384: ed54829ae548bac034d3faeb65d6c95917592291f7cab6ba272bdeeb0fe9247783578d373777daf573125edfa78fe9fe
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-11-09 18:03:59

Version Info:

0: [No Data]

Generic.PySpy.A.F3B868AB also known as:

CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Agent.Script.1642598
BitDefenderGeneric.PySpy.A.F3B868AB
ESET-NOD32Python/PSW.Agent.EN
KasperskyHEUR:Trojan-PSW.Python.Nuker.gen
MicroWorld-eScanGeneric.PySpy.A.F3B868AB
AvastPython:PWStealer-A [Spy]
Ad-AwareGeneric.PySpy.A.F3B868AB
EmsisoftGeneric.PySpy.A.F3B868AB (B)
DrWebPython.Stealer.194
McAfee-GW-EditionBehavesLike.Win64.Ransom.vc
FireEyeGeneric.mg.52dc3e1bd6e81937
GDataGeneric.PySpy.A.F3B868AB
JiangminTrojan.Agentb.kqi
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.34CE845
ArcabitGeneric.PySpy.A.F3B868AB
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGeneric.PySpy.A.F3B868AB
MalwarebytesSpyware.DiscordStealer.Python
FortinetPython/Agent.BP!tr
AVGPython:PWStealer-A [Spy]

How to remove Generic.PySpy.A.F3B868AB?

Generic.PySpy.A.F3B868AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment