Trojan

TrojanPSW.Egspy removal tips

Malware Removal

The TrojanPSW.Egspy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPSW.Egspy virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine TrojanPSW.Egspy?


File Info:

crc32: 5842C87A
md5: 97b9dc9307b3459081c139a1e5a7175b
name: primux.exe
sha1: 9533d4ffea5d04c1218df4b38ae73fa72649a49d
sha256: 869166d2b4f937e15ab0cf089fce6833bdadf41c495eb942745de1ff7107c2af
sha512: 6b49409432b56cd25fb7ca2542fe94254f2741db7dbdaba46932e57b40fae23044a86403f7da6aff807dcf4ef6e92aa50f522c35c76f1cdcdb437c097f9f03c4
ssdeep: 196608:M2Z84TwANaWanh804vVABxgKv09k+HCnHF00Gi9H:x5wh49ABxgKM9kAz0N
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (c) 1995-2012 Gerdes Aktiengesellsc
WebSite: http://www.primuxisdn.de
InternalName: SetupPro
FileVersion: 2012.4.26.1744
CompanyName: Gerdes Aktiengesellschaft
SpecialBuild:
ProductName: PrimuX ISDN
ProductVersion: 3.6.5201
FileDescription: TIN Setup
Email: service@gerdes-ag.de
OriginalFilename: SETUPPRO.EXE
Translation: 0x0409 0x04b0

TrojanPSW.Egspy also known as:

ClamAVWin.Trojan.Genome-8229
VBA32TrojanPSW.Egspy

How to remove TrojanPSW.Egspy?

TrojanPSW.Egspy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment