Spy

Win32/Spy.Agent.PYU (file analysis)

Malware Removal

The Win32/Spy.Agent.PYU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.PYU virus can do?

  • Presents an Authenticode digital signature
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients

How to determine Win32/Spy.Agent.PYU?


File Info:

crc32: D8F6E251
md5: 83a82cacf8a42eb833b95c0985095457
name: 83A82CACF8A42EB833B95C0985095457.mlw
sha1: d07493ef698766e82d5f5dff6b95c2dcd3537fb0
sha256: 1efa74e72060865ff07bda90c4f5d0c470dd20198de7144960c88cef248c4457
sha512: c69701581ff7fc10c3e1270a2b3822fa7faa24105848e9c9f129b45f0543ddfc8739adaac1a0277a2c9f7565b0ea043f7f3ed3630ba44a246dccdb7a59725efb
ssdeep: 12288:VoJqNIPtNmO6IOOEp0TMlja7NRl2PSVikIyoyueh+AkHcnLwuukoCOD6zlFjOz+2:VoJEKZ6IEGTMxapRl2PSwHTehy6BG+p4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Spy.Agent.PYU also known as:

K7AntiVirusSpyware ( 005687121 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.18689
CynetMalicious (score: 100)
ALYacGen:Variant.Stealer.7
CylanceUnsafe
ZillyaTrojan.Bobik.Win32.2070
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanSpy:Win32/StellarStealer.d5e1f082
K7GWSpyware ( 005687121 )
Cybereasonmalicious.cf8a42
CyrenW32/Trojan2.QDAM
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PYU
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Zusy-9812688-0
KasperskyHEUR:Trojan-Spy.Win32.Bobik.gen
BitDefenderGen:Variant.Stealer.7
NANO-AntivirusTrojan.Win32.Bobik.innsnn
MicroWorld-eScanGen:Variant.Stealer.7
TencentMalware.Win32.Gencirc.10ce2a40
Ad-AwareGen:Variant.Stealer.7
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34670.QqY@aW0S6vo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXMZ-DZ!83A82CACF8A4
FireEyeGeneric.mg.83a82cacf8a42eb8
EmsisoftTrojan-Spy.Agent (A)
JiangminTrojanSpy.Bobik.mi
AviraHEUR/AGEN.1141176
MicrosoftTrojan:Win32/StellarStealer.SBR!MSR
GridinsoftSpy.Win32.Keylogger.oa!s1
ArcabitTrojan.Stealer.7
AegisLabTrojan.Win32.Bobik.l!c
GDataWin32.Trojan.PSE.3YNIAA
AhnLab-V3Trojan/Win32.RL_Stealer.R355109
McAfeeGenericRXMZ-DZ!83A82CACF8A4
MAXmalware (ai score=89)
VBA32TrojanSpy.Bobik
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDA21
RisingSpyware.Agent!8.C6 (C64:YzY0OtP2hpfCUG2A)
IkarusTrojan-Spy.Agent
FortinetW32/GenKryptik.EZNX!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Bobik.HgIASScA

How to remove Win32/Spy.Agent.PYU?

Win32/Spy.Agent.PYU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment