Malware

Python/PSWTool.Passdec.Z potentially unsafe information

Malware Removal

The Python/PSWTool.Passdec.Z potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/PSWTool.Passdec.Z potentially unsafe virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Python/PSWTool.Passdec.Z potentially unsafe?


File Info:

name: 340D5990872DD0BA9995.mlw
path: /opt/CAPEv2/storage/binaries/ff5ec8b165a32841228c01d76f26a5697d8548e30b82d211fa42fc728a940cc8
crc32: 83C17CF3
md5: 340d5990872dd0ba999509710b1af127
sha1: e9700a8450c13e3359bbc44fb6161f5d54abdf1f
sha256: ff5ec8b165a32841228c01d76f26a5697d8548e30b82d211fa42fc728a940cc8
sha512: 53fd1d87f06357573445228aed945f66575c961ed4bfb53526204c8dffb1caea3ba92c30edad965d5156fca500ed2e432fa5ebc84d6675853c01a22ba941ed0c
ssdeep: 393216:itwR5p9WjVP1UricCyCdNvztJNvCgDHwzV7n1u3jWZJt:C04j11UricCyCdNxJNVDHGn1Y
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T164D6333511A0982EC1F05A3A0467FF751C7EDD192B50E8B7A3CD1B772EE68D0A538E98
sha3_384: 112d577bcbb735c4ec816b0a34744bd0831dec39dce9ef7b114f101ab0c7afa0bbe7b18d11658dbece980847accfa002
ep_bytes: e8a0040000e968feffff558bec6a00ff
timestamp: 2022-06-01 02:55:52

Version Info:

0: [No Data]

Python/PSWTool.Passdec.Z potentially unsafe also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
McAfeeArtemis!340D5990872D
Cylanceunsafe
ZillyaWorm.Cridex.Win32.965
SangforTrojan.Win32.Agent.Vft8
K7GWUnwanted-Program ( 005a9d371 )
ESET-NOD32Python/PSWTool.Passdec.Z potentially unsafe
APEXMalicious
KasperskyHEUR:Trojan-PSW.Python.Agent.gen
AvastWin32:Malware-gen
F-SecureTrojan.TR/PSW.Agent.ruzft
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
JiangminTrojan.PSW.Python.hj
AviraTR/PSW.Agent.ruzft
Antiy-AVLTrojan[Exploit]/Python.Leivion
ZoneAlarmHEUR:Trojan-PSW.Python.Agent.gen
TrendMicro-HouseCallTROJ_GEN.R002H07GP23
TencentWin32.Trojan-QQPass.QQRob.Cgow
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Python/PSWTool.Passdec.Z potentially unsafe?

Python/PSWTool.Passdec.Z potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment