Malware

What is “PWS:Win32/Dozmot.D”?

Malware Removal

The PWS:Win32/Dozmot.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Dozmot.D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Dozmot.D?


File Info:

name: 1EC7C87F3D0FA0F653C9.mlw
path: /opt/CAPEv2/storage/binaries/1168b37903a43540d6e7e938347b06326798646a41188c47300f5ce8cff41a15
crc32: CA058F8A
md5: 1ec7c87f3d0fa0f653c9137aeaceead5
sha1: a0916a8c514839448fe7a3af8b773cf477a41b86
sha256: 1168b37903a43540d6e7e938347b06326798646a41188c47300f5ce8cff41a15
sha512: 104e2586db28ed72a3d46546537fc7b994c20451b9817a2ad7be4f0e76d1560d71833d666bd2ce22794615fcde76ddf86a48993ce6b745193aa7839549ce824e
ssdeep: 384:3URip4fF59v9s37Hg4Ut3mRTBqKiFGbrNAHo9B:3URo4fFXv27XU4vMQXNQo
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T12662D0602B9C5C12C834037F174B53B7616E2904B1FFCBF23E6E242F0D696626EAC964
sha3_384: 1579e730af969da7583acd75ea61b9be4f79b3afe003ec2552647a40a0d62e09f11adfdaabb9c88c267aaa1d4eb8ba9e
ep_bytes: 668bc053609ceb01ff8bc0b902002300
timestamp: 2010-04-22 08:30:43

Version Info:

0: [No Data]

PWS:Win32/Dozmot.D also known as:

LionicTrojan.Win32.GameThief.d!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Magania.4
ClamAVWin.Trojan.Wow-42
FireEyeGeneric.mg.1ec7c87f3d0fa0f6
SkyhighBehavesLike.Win32.Generic.lc
McAfeeBackDoor-EGP
Cylanceunsafe
ZillyaTrojan.WOW.Win32.6906
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanPSW:Win32/Dozmot.c5b12de6
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36744.am4@aGcZvMp
VirITBackdoor.Win32.Generic.BHEB
SymantecInfostealer.Gampass
tehtrisGeneric.Malware
ESET-NOD32Win32/PSW.OnLineGames.QIU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.WOW.iol
BitDefenderGen:Variant.Magania.4
NANO-AntivirusTrojan.Win32.WOW.bezyq
AvastWin32:Trojan-gen
TencentWin32.Trojan-GameThief.WOW.Hjgl
TACHYONTrojan-PWS/W32.WebGame.14848.KA
SophosMal/Medfos-K
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.PWS.Gamania.25176
VIPREGen:Variant.Magania.4
TrendMicroTROJ_GAMETHI.GFE
EmsisoftGen:Variant.Magania.4 (B)
IkarusTrojan-GameThief.Win32.Magania
GDataGen:Variant.Magania.4
JiangminTrojan/Pakes.jvz
WebrootW32.Malware.gen
VaristW32/Agent.GV.gen!Eldorado
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
KingsoftWin32.Troj.Undef.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Magania.4
ViRobotTrojan.Win32.PSWWow.14848.L
ZoneAlarmTrojan-GameThief.Win32.WOW.iol
MicrosoftPWS:Win32/Dozmot.D
GoogleDetected
AhnLab-V3Win-Trojan/Onlinegamehack23.Gen
ALYacGen:Variant.Magania.4
MAXmalware (ai score=99)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GAMETHI.GFE
RisingTrojan.PSW.Win32.Sousuke.a (CLASSIC)
YandexTrojan.GenAsa!xtzW4BKbwnk
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1432107.susgen
FortinetW32/Kryptik.AWW!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove PWS:Win32/Dozmot.D?

PWS:Win32/Dozmot.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment