Spy

Spyware.Pskill.B removal guide

Malware Removal

The Spyware.Pskill.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Pskill.B virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Spyware.Pskill.B?


File Info:

name: 9507AC10FEBCADEE1244.mlw
path: /opt/CAPEv2/storage/binaries/51abd349d812d56273d45e3f775f672ffb62efdd6dd99d454b026c2118930ec3
crc32: 469F79D0
md5: 9507ac10febcadee124455bffca7d0bb
sha1: ad6d51a6d3c4215378fab977afc7af0d246cd0ad
sha256: 51abd349d812d56273d45e3f775f672ffb62efdd6dd99d454b026c2118930ec3
sha512: 82efaf2ad06a19b7e7308946c7e52c736283ea62245eabac30853c810af0a689d951a65190ec8813d55617e88b3f7ab9208d211edb74a0f913a0281baa37bca7
ssdeep: 768:Jvp9wkPk4bP/MPOj1UUjQvmSow8gQ4rp:JvzwkPnD//1Ljcmmp
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T110F2E0B81268841FE2F725322BF793D25778F1965F73836E4390225E1C56C095BE1AF2
sha3_384: d6a227b839414051f8259104383541eb52c27a43d5ef13689dac2628e17fed591592630d1cbe9126bc003997ef19db9c
ep_bytes: 60be00a041008dbe0070feff5783cdff
timestamp: 2004-12-03 12:20:23

Version Info:

Comments:
CompanyName: Sysinternals - www.sysinternals.com
FileDescription: Terminates processes on local or remote systems
FileVersion: 1.10
InternalName: PsKill
LegalCopyright: Copyright (C) 1999-2004 Mark Russinovich
LegalTrademarks:
OriginalFilename: pkill.exe
PrivateBuild:
ProductName: Systems Internals pkill
ProductVersion: 1.10
SpecialBuild:
Translation: 0x0409 0x04b0

Spyware.Pskill.B also known as:

LionicRiskware.Win32.PsKill.1!c
CynetMalicious (score: 99)
CAT-QuickHealTrojan.GenericPMF.S3118006
ALYacSpyware.Pskill.B
VIPREPsKill (not malicious)
SangforHacktool.Win32.PsKill.buxin
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRiskWare:Win32/PsKill.ca38226f
K7GWRiskware ( 0040eff71 )
CyrenW32/Tool.IJUX-1683
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Tool.Pskill-11
BitDefenderSpyware.Pskill.B
NANO-AntivirusRiskware.Win32.PsKill.gskua
MicroWorld-eScanSpyware.Pskill.B
RisingTrojan.Bitrep!8.F596 (CLOUD)
EmsisoftSpyware.Pskill.B (B)
ComodoApplicUnsaf.Win32.RiskTool.PsKill.efr@3xrono
F-SecurePrivacyRisk.SPR/PsKill.B
DrWebProgram.PsKill.101
FireEyeSpyware.Pskill.B
SophosPsKill (PUA)
JiangminRiskTool.PsKill.b
WebrootW32.Spyware.Gen
AviraSPR/PsKill.B
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.E86D
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C51
GDataSpyware.Pskill.B
AhnLab-V3Win-AppCare/PsKill.122880
TACHYONAbuse-Worry/W32.PsKill.122880
VBA32Riskware.Win32.PsKill
CylanceUnsafe
PandaGeneric Suspicious
YandexTrojan.GenAsa!ewOGlz7xNd4
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/PSKill
AVGWin32:Malware-gen
Cybereasonmalicious.0febca
AvastWin32:Malware-gen

How to remove Spyware.Pskill.B?

Spyware.Pskill.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment