Spy

Spyware.PasswordStealer.XMP.Generic malicious file

Malware Removal

The Spyware.PasswordStealer.XMP.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Spyware.PasswordStealer.XMP.Generic virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window

How to determine Spyware.PasswordStealer.XMP.Generic?


File Info:

crc32: CDCE1DFC
md5: 51a3af0843364aeda930476ebaf3102f
name: lky.exe
sha1: 439dcaf280b2384060ed9237dce68fabdce39031
sha256: 4acc26b5f79c556cbb1a396ea8666739e8992399739e6179e216cf52b81a5821
sha512: f3f5ba5dbda7aa68092d7986b31b1faeba89ddf938e2482ac056902c97d2e9cd62ea527e447ab97a19eecbdcfb6a5b6aaed4a3aa6eb8350d5c8b188d0da22848
ssdeep: 3072:bdBqF5acKBBYQ02ulECxAkYTRmXVQp0HhdJkhtvIHEv84qDbKW/UN0XWp1KbIe81:btbOljxHQqhdJkhYYqqWm0XKP1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) coggers 2019
InternalName: sulphostannate.exe
FileVersion: 8.4.1.3
CompanyName: Teena
ProductName: fatten
ProductVersion: 8.1.7.3
FileDescription: paraconic
OriginalFilename: ilama.exe
Translation: 0x0409 0x04b0

Spyware.PasswordStealer.XMP.Generic also known as:

MicroWorld-eScanTrojan.GenericKD.32648454
FireEyeGeneric.mg.51a3af0843364aed
CAT-QuickHealBackdoor.Androm
McAfeeRDN/Generic BackDoor
MalwarebytesSpyware.PasswordStealer.XMP.Generic
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Androm.m!c
K7AntiVirusTrojan ( 0055a6c31 )
BitDefenderTrojan.GenericKD.32648454
K7GWTrojan ( 0055a6c31 )
Cybereasonmalicious.280b23
BitDefenderThetaGen:NN.ZexaF.32245.ny3@aKbRpSli
CyrenW32/Trojan.AEYL-6519
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R015C0WJR19
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.tkqj
AlibabaBackdoor:Win32/Androm.eb287adc
NANO-AntivirusTrojan.Win32.Azorult.getfyz
ViRobotTrojan.Win32.Z.Agent.226390
RisingTrojan.Kryptik!1.BE72 (CLASSIC)
Ad-AwareTrojan.GenericKD.32648454
SophosMal/Generic-S
ComodoMalware@#t55d2yozc5nq
F-SecureHeuristic.HEUR/AGEN.1039972
DrWebTrojan.PWS.Stealer.25838
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Expiro.dc
SentinelOneDFI – Malicious PE
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.32648454 (B)
APEXMalicious
GDataTrojan.GenericKD.32648454
JiangminTrojan.PSW.Azorult.epd
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1039972
Antiy-AVLTrojan[Backdoor]/Win32.Androm
MicrosoftTrojan:Win32/Azorult.PC!MTB
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F22D06
ZoneAlarmBackdoor.Win32.Androm.tkqj
AhnLab-V3Malware/Win32.Generic.C3534682
Acronissuspicious
VBA32Backdoor.Androm
ALYacSpyware.LokiBot
MAXmalware (ai score=83)
CylanceUnsafe
ESET-NOD32a variant of Win32/GenKryptik.DWIQ
YandexBackdoor.Androm!YbuuBkppCIY
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.GWYH!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.0f6

How to remove Spyware.PasswordStealer.XMP.Generic?

Spyware.PasswordStealer.XMP.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment