Spy

What is “Spyware.Echelon”?

Malware Removal

The Spyware.Echelon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Echelon virus can do?

  • Network activity detected but not expressed in API logs

How to determine Spyware.Echelon?


File Info:

crc32: 2406956F
md5: 550b37b4d263f0fcb4e16f999e19a7f8
name: upload_file
sha1: e8598cadf6dc079756ff7e322092c540711c34cc
sha256: 3ccfba4ea524addfcbe7be67231761b6c066e030d25a5ad45d2d20a8d8deb1d1
sha512: bb38ccc6be0286dbe3b84d87274013d722a4a40802021f4712f4e5c2787d1e08275ac15e1a1c8dfda6867d7f8fb7c3003939d66158a6b4ddb8c13dc05915504b
ssdeep: 12288:R0J6OcpFoLiHkB6Hv6aTwD/u6/PmRs9vlL+BkebeKqroEBKvfszILmcPQcPvhJh:R0cuUHCaaf+ZBF6cPQsvXMSEO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: paulo.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: paulo.exe

Spyware.Echelon also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.52
MicroWorld-eScanTrojan.GenericKD.34358028
FireEyeGeneric.mg.550b37b4d263f0fc
CAT-QuickHealTrojanpws.Msil
Qihoo-360Generic/HEUR/QVM03.0.3BC9.Malware.Gen
ALYacBackdoor.MSIL.Quasar.gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056c69a1 )
BitDefenderTrojan.GenericKD.34358028
K7GWTrojan ( 0056c69a1 )
Cybereasonmalicious.df6dc0
TrendMicroTROJ_GEN.R014C0PHF20
BitDefenderThetaGen:NN.ZemsilF.34186.vo0@aqS6zEi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R014C0PHF20
KasperskyHEUR:Trojan-PSW.MSIL.Coins.gen
AlibabaTrojanPSW:MSIL/Kryptik.40b12b49
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.34358028
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Crypt.XDR.Gen
FortinetMSIL/Kryptik.XHV!tr
SophosMal/Generic-S
IkarusTrojan-Spy.Keylogger.AgentTesla
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D20C430C
ZoneAlarmHEUR:Trojan-PSW.MSIL.Coins.gen
MicrosoftTrojan:MSIL/AgentTesla.Z!MTB
CynetMalicious (score: 85)
McAfeeArtemis!550B37B4D263
MalwarebytesSpyware.Echelon
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of MSIL/Kryptik.XII
TencentMsil.Trojan-qqpass.Qqrob.Ssqt
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
GDataTrojan.GenericKD.34358028
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Spyware.Echelon?

Spyware.Echelon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment