Malware

Win64/PSW.Discord.J information

Malware Removal

The Win64/PSW.Discord.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/PSW.Discord.J virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Singapore)
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win64/PSW.Discord.J?


File Info:

crc32: 75878429
md5: b6b064e285fe3b6d0108b9ae0d980b2a
name: B6B064E285FE3B6D0108B9AE0D980B2A.mlw
sha1: ecddfce4d240a0023c4eef5fbb9cf1d6adc8c2aa
sha256: 3e166127fd8c239d81559655c2778c607a7e492ee216c0223cafa8cc90c05599
sha512: 593d5fc502a32192f0615d191b1face52cb81045154357bbc4d7a270ac98a7f0cd6cedc2f555a59fc56122ca5d4d51a92f25a05016966de51aadc40f85ca667d
ssdeep: 6144:FodQN1u/pWgHaNmxASyo05qhEJpzlYW9qV0OOY14gX:gQTu/pWMaNmxIqrWSOY14E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020b 0x052b

Win64/PSW.Discord.J also known as:

K7AntiVirusPassword-Stealer ( 00580d2c1 )
LionicTrojan.Win32.Disco.i!c
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37380810
AlibabaTrojanPSW:Win32/Disco.d5397af4
K7GWPassword-Stealer ( 00580d2c1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/PSW.Discord.J
APEXMalicious
AvastWin64:Trojan-gen
KasperskyTrojan-PSW.Win32.Disco.cfn
BitDefenderTrojan.GenericKD.37380810
MicroWorld-eScanTrojan.GenericKD.37380810
Ad-AwareTrojan.GenericKD.37380810
SophosMal/Generic-S (PUA)
TrendMicroTROJ_GEN.R002C0WHD21
McAfee-GW-EditionBehavesLike.Win64.BadFile.cm
FireEyeTrojan.GenericKD.37380810
EmsisoftTrojan.GenericKD.37380810 (B)
AviraTR/Redcap.nafea
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.37380810
McAfeeArtemis!20E27F907321
MAXmalware (ai score=81)
VBA32TrojanPSW.Disco
MalwarebytesMalware.AI.4227310987
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WHD21
YandexTrojan.PWS.Disco!n8NL0i+O9to
IkarusTrojan-PSW.Discord
FortinetW32/Discord.J!tr.pws
AVGWin64:Trojan-gen

How to remove Win64/PSW.Discord.J?

Win64/PSW.Discord.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment