Spy

About “Spyware.PasswordStealer.GO” infection

Malware Removal

The Spyware.PasswordStealer.GO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.PasswordStealer.GO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Spyware.PasswordStealer.GO?


File Info:

name: 76251E256B86A39E55B6.mlw
path: /opt/CAPEv2/storage/binaries/481f455ead17a67e5b8f41fac6fe261f89b6367b60ee5844358949f52bee54a6
crc32: D16AF363
md5: 76251e256b86a39e55b6c2f3ae607aa7
sha1: 72114fb8213ff77d927d503b2404e8f5ca3e9ed7
sha256: 481f455ead17a67e5b8f41fac6fe261f89b6367b60ee5844358949f52bee54a6
sha512: b3daa49dc4eb95b38710841a1e3b61a5ad3090c372d249fd1beb5eb734b03f9f3ff5d333fc0df91f6422cb6ddac0917710c75927b3779d4ef9347b0f8a77874d
ssdeep: 49152:qAbgdWmlk6CF0hpJ8NvSRIa/jBSV5luJ+1BhjBGEy+o46lv6aDGf5:qAUd/NnF8gWa25h1/YEf76x6aDGf
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1B1D533EBE17BE571EA251F7D2876C26071EEC475694A3C9A0380EE47837B1B12C62D18
sha3_384: dc53b2c4b7c85aa4b343dd79d1fb43406ae4e133d18fd2358c18f88d67ea3d092cdb9ec04ec6d113c57fbee8530622e5
ep_bytes: 53565755488d35da54d4ff488dbedbcf
timestamp: 2021-10-15 18:50:26

Version Info:

0: [No Data]

Spyware.PasswordStealer.GO also known as:

LionicTrojan.Win32.Disco.i!c
CynetMalicious (score: 100)
FireEyeTrojan.GenericKD.37832300
McAfeeArtemis!76251E256B86
CylanceUnsafe
SangforInfostealer.Win32.Disco.fnz
K7AntiVirusTrojan ( 0057b4871 )
AlibabaTrojanPSW:Win32/Disco.ea0dabea
K7GWTrojan ( 0057b4871 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of WinGo/PSW.Agent.J
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Disco.fnz
BitDefenderTrojan.GenericKD.37832300
MicroWorld-eScanTrojan.GenericKD.37832300
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.37832300
EmsisoftTrojan.GenericKD.37832300 (B)
TrendMicroTROJ_GEN.R002C0WJN21
McAfee-GW-EditionBehavesLike.Win64.Trickbot.vc
SophosMal/Generic-S
GDataTrojan.GenericKD.37832300
JiangminTrojan.PSW.Disco.bna
AviraTR/Redcap.fgtrv
Antiy-AVLTrojan/Generic.ASMalwS.34B9990
GridinsoftRansom.Win64.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.GenericKD.37832300
MAXmalware (ai score=84)
MalwarebytesSpyware.PasswordStealer.GO
TrendMicro-HouseCallTROJ_GEN.R002C0WJN21
IkarusTrojan-PSW.Agent
FortinetMalicious_Behavior.SB
AVGWin64:Trojan-gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Spyware.PasswordStealer.GO?

Spyware.PasswordStealer.GO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment