Spy

Win32/Spy.POSCardStealer.K removal guide

Malware Removal

The Win32/Spy.POSCardStealer.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.POSCardStealer.K virus can do?

  • Network activity detected but not expressed in API logs

How to determine Win32/Spy.POSCardStealer.K?


File Info:

crc32: 3963365F
md5: 0ae07aa804a40316dbbabbcbccce1d14
name: new.exe
sha1: 73a06cfe8931ce49e5e54e56457737a422c52a88
sha256: 7be8f15c190b5de51296a24373b49adfe0c9cc41eeb658f0831410782a9a78e1
sha512: 1c779649aadb29d36ab6810c90664f19f47b9502c9e7e80cd46e0225fcd6fc4f962c129cdfa2545b3ee5bc5890311695435a29c6ed1e6e43f377bdc9f03c48a0
ssdeep: 3072:/7Nkvd/Sy6dEvIz0pYl+jbzi8TumnR5WQwwK9J6yQ7nBxi:/7Nk116dEEtQbzi8hnLjKDqxi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Spy.POSCardStealer.K also known as:

BkavW32.WpechkLTD.Trojan
MicroWorld-eScanGen:Trojan.Malware.jyW@aeefmjji
FireEyeGeneric.mg.0ae07aa804a40316
CAT-QuickHealTrojan.MauvaiseRI.S5247814
McAfeePWS-FATT!0AE07AA804A4
CylanceUnsafe
VIPREBackdoor.Win32.Hesetox.a (v)
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusSpyware ( 004308c01 )
AlibabaBackdoor:Win32/Hesetox.c8661e1e
K7GWSpyware ( 004308c01 )
Cybereasonmalicious.804a40
TrendMicroBKDR_HESETOX.SMJ
CyrenW32/Dapato.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:VSkimmer-A [Trj]
ClamAVWin.Trojan.Agent-1202695
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Malware.jyW@aeefmjji
NANO-AntivirusTrojan.Win32.Vskim.cqipth
ViRobotBackdoor.Win32.Hesetox.160260
RisingBackdoor.Hesetox!8.10FD (CLOUD)
Endgamemalicious (high confidence)
SophosTroj/Trackr-D
ComodoMalware@#21q25dv1upw7b
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader8.15980
ZillyaDropper.Dapato.Win32.16801
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Malware.jyW@aeefmjji (B)
IkarusTrojan.Win32.Malex
F-ProtW32/Dapato.D.gen!Eldorado
JiangminTrojan/Generic.arvjq
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
FortinetW32/Generic.AC.5EAE9!tr
Antiy-AVLTrojan[Dropper]/Win32.Dapato
MicrosoftBackdoor:Win32/Hesetox.A
SUPERAntiSpywareTrojan.Agent/Gen-Malex
ZoneAlarmHEUR:Trojan.Win32.Generic
TACHYONTrojan-Spy/W32.Vskim.160256
AhnLab-V3Win-Trojan/Hesetox.160256
Acronissuspicious
VBA32TrojanSpy.Vskim
ALYacGen:Trojan.Malware.jyW@aeefmjji
MAXmalware (ai score=100)
Ad-AwareGen:Trojan.Malware.jyW@aeefmjji
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Spy.POSCardStealer.K
TrendMicro-HouseCallBKDR_HESETOX.SMJ
TencentMalware.Win32.Gencirc.10b7d380
YandexTrojan.Agent!sNqLqB01e+w
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
GDataGen:Trojan.Malware.jyW@aeefmjji
BitDefenderThetaAI:Packer.FB368C231F
AVGWin32:VSkimmer-A [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.0bf

How to remove Win32/Spy.POSCardStealer.K?

Win32/Spy.POSCardStealer.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment