Spy

Should I remove “Win64/Spy.POSCardStealer.AN”?

Malware Removal

The Win64/Spy.POSCardStealer.AN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Spy.POSCardStealer.AN virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • The executable used a known stolen/malicious Authenticode signature
  • Anomalous binary characteristics

How to determine Win64/Spy.POSCardStealer.AN?


File Info:

crc32: 271F18DD
md5: aa87ab0c51887b86b48c009931dcc410
name: AA87AB0C51887B86B48C009931DCC410.mlw
sha1: 9c07abbe2fb698adbc5d1305645d42884fa1b840
sha256: dc8191d0deea9aa5c25fa88b1e362548b80fe9cafe433974c135c0de69b6d799
sha512: ad3008b2cc59b002d5949b638a746228026f23d2b60b58d731c439e073cd8a44f7f0415ebc68b31a5dde0543f84321068158c8df0cf0238bcbaa3eaa651fcc32
ssdeep: 6144:LvQl1wTN/E6CeqYAN/Vm/cr3/CXZj/LqIgpec6ysllES1+7yq/hhj34:Lc41MN/VNCXZj/LqIVcRsLOJh8
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

0: [No Data]

Win64/Spy.POSCardStealer.AN also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ALYacTrojan.Autoruns.GenericKD.42728864
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanSpy:Win64/POSCardStealer.55e65c99
Cybereasonmalicious.c51887
SymantecTrojan.Gen.2
ESET-NOD32Win64/Spy.POSCardStealer.AN
APEXMalicious
AvastWin64:Malware-gen
BitDefenderTrojan.Autoruns.GenericKD.42728864
MicroWorld-eScanTrojan.Autoruns.GenericKD.42728864
Ad-AwareTrojan.Autoruns.GenericKD.42728864
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic PWS.cf
FireEyeGeneric.mg.aa87ab0c51887b86
EmsisoftTrojan.Autoruns.GenericKD.42728864 (B)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Autoruns.GenericKD.42728864
McAfeeRDN/Generic PWS.cf
MAXmalware (ai score=99)
YandexTrojanSpy.POSCardStealer!6oNFiNUS1Ww
IkarusTrojan-Spy.Win64.Agent
AVGWin64:Malware-gen
Paloaltogeneric.ml

How to remove Win64/Spy.POSCardStealer.AN?

Win64/Spy.POSCardStealer.AN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment