Malware

Win64/PSW.Discord.U removal instruction

Malware Removal

The Win64/PSW.Discord.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/PSW.Discord.U virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win64/PSW.Discord.U?


File Info:

name: 8C5F8C4C37CB1E5D7F74.mlw
path: /opt/CAPEv2/storage/binaries/8bcc779a309c348e97219b2d8f42813d5c85c0a5ab64f67a99bb95b5b733e1d3
crc32: 681D3A0C
md5: 8c5f8c4c37cb1e5d7f74f32fd9c72719
sha1: 09ab413caf463aae514803715900e92d50f6ae52
sha256: 8bcc779a309c348e97219b2d8f42813d5c85c0a5ab64f67a99bb95b5b733e1d3
sha512: 8af8841dbdbd028e5f69590a434831315d53aafd0433c7e8ed5cb5fad4da9e74f92d0107042dd400b104a0c13e4b4c374c3da4fbc6124a92dc11deaca92ae132
ssdeep: 12288:7O8vdUavq8ScEIhoJjEdD2gp5eP+Ppt9xRrCSF:7Pxvq8Zh2gp5eP+Ppt9xRrCSF
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T146B47728367905A5E175C07AE94687AACDA07046133D94FBD281C9D8BF703EC6F7CB62
sha3_384: d6e198a11573932d672f87cc7956d2f11af65a02b66b107650999b6208a01d5dd50f937372ba55f09dae65f88ad089a0
ep_bytes: e90ef70400e969640100e9b48e0200e9
timestamp: 2021-12-05 13:21:35

Version Info:

0: [No Data]

Win64/PSW.Discord.U also known as:

MicroWorld-eScanTrojan.GenericKD.47571037
FireEyeTrojan.GenericKD.47571037
CAT-QuickHealTrojanpws.Disco
McAfeeRDN/Generic PWS.y
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 0058b73d1 )
AlibabaTrojanPSW:Win32/Disco.fc62f0ac
K7GWPassword-Stealer ( 0058b73d1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/PSW.Discord.U
TrendMicro-HouseCallTROJ_GEN.R011C0GL821
KasperskyTrojan-PSW.Win32.Disco.iaf
BitDefenderTrojan.GenericKD.47571037
AvastWin64:Trojan-gen
TencentWin32.Trojan-qqpass.Qqrob.Ecax
Ad-AwareTrojan.GenericKD.47571037
EmsisoftTrojan.GenericKD.47571037 (B)
TrendMicroTROJ_GEN.R011C0GL821
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
APEXMalicious
AviraTR/Redcap.lnxqm
Antiy-AVLTrojan/Generic.ASMalwS.34EB97C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Agent.539136.LI
GDataTrojan.GenericKD.47571037
CynetMalicious (score: 99)
VBA32TrojanPSW.Disco
ALYacTrojan.GenericKD.47571037
MAXmalware (ai score=85)
MalwarebytesSpyware.PasswordStealer.Discord
IkarusTrojan-PSW.Discord
FortinetW64/Discord.U!tr.pws
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Win64/PSW.Discord.U?

Win64/PSW.Discord.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment