Spy

Win32/Spy.Agent.PYV removal

Malware Removal

The Win32/Spy.Agent.PYV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.PYV virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Writes a potential ransom message to disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Spy.Agent.PYV?


File Info:

crc32: 4055E3CF
md5: 022504ea77e78ece59ef88c88e73e697
name: video_axv.exe
sha1: 640454792d3c06f8fd3fab00a4bb4b99be11275d
sha256: d8442692e79604619ccee628ff1e76c0e6f0ef01715e6e56ed0ef26d11e21e55
sha512: 519e6628ec3d7c3a304dfa372aba3caa66afc37853a599859fe23a18aec66f8d248405a277744129c81fc48a7ad0443c614051ba10a1a82e73225f86e988535d
ssdeep: 12288:bplIvYVih0kKYIEXrejlfx2ykG8n1vQC5exIhx:bpeaihpI7X2rYFIhx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Spy.Agent.PYV also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Trojan.Heur.RP.AuW@bSu!mQfj
FireEyeGeneric.mg.022504ea77e78ece
CAT-QuickHealTrojan.Generic
McAfeeRDN/Generic PWS.y
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0056c7821 )
BitDefenderGen:Trojan.Heur.RP.AuW@bSu!mQfj
K7GWSpyware ( 0056c7821 )
CrowdStrikewin/malicious_confidence_60% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Generic.387f6660
RisingSpyware.Agent!8.C6 (CLOUD)
Ad-AwareGen:Trojan.Heur.RP.AuW@bSu!mQfj
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Spy.Agent.wzutp
DrWebTrojan.Siggen10.4348
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WHE20
SophosMal/Generic-S
IkarusTrojan.Spy.Stealer
JiangminTrojan.PSW.Mimikatz.bio
AviraTR/Spy.Agent.wzutp
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Generic
MicrosoftTrojan:Win32/Ymacco.AAD8
ArcabitTrojan.Heur.RP.EDD11FD
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.RP.AuW@bSu!mQfj
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.16915DF51F
VBA32Trojan.Ymacco
MalwarebytesSpyware.Agent
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Spy.Agent.PYV
TrendMicro-HouseCallTROJ_GEN.R002C0WHE20
TencentWin32.Trojan.Generic.Bnp
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.a77e78
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM41.2.3C57.Malware.Gen

How to remove Win32/Spy.Agent.PYV?

Win32/Spy.Agent.PYV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment