Malware

How to remove “PWS:Win32/Karagany.A”?

Malware Removal

The PWS:Win32/Karagany.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Karagany.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Karagany.A?


File Info:

name: 3338790352579338C5C2.mlw
path: /opt/CAPEv2/storage/binaries/1ec4878ff51a89392c0d5769d526df5b138dffa4b62303faee5e2ec9a3e3d611
crc32: 4AB77246
md5: 3338790352579338c5c2f3cf6dc9fb29
sha1: c5acc873ede36f6f0267fc14b1c6569da5a34e62
sha256: 1ec4878ff51a89392c0d5769d526df5b138dffa4b62303faee5e2ec9a3e3d611
sha512: 6bd9416b1123e9251c1ac934fb01bcd12e9d6cd916b5de6947dc38d38663616386dc985b5bfaca973232eaeec28d4f8ae8e957370f31af4b14ea757cfa4f73eb
ssdeep: 12288:FBaNJVImQOgVsF5d9QfR8vNIvGnPC1I9MaAfrVln2udQEMjftz:u1I1VibmcN5nZ9MnzT3d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FCE42375F6D3BCA5E8A825733717BCC30372B6BA340C1B5FBBA8624949CE3412518979
sha3_384: ed6ab24af4f7fd4e726acf3c15c9e15614bd0ada605970db0ec95076912f5cf30e919601c392e8507b04d196cbf1e54a
ep_bytes: 60be00c045008dbe0050faff57eb0b90
timestamp: 2009-01-18 20:33:08

Version Info:

CompanyName: Cronosoft
FileDescription: Bulk Hairy Tsp Ham Tab
FileVersion: 6.10
InternalName: Vodka Clog Ash
LegalCopyright: Paths © Waved Briny 2003-2008
OriginalFilename: Mare.exe
ProductName: Save Simms Darn
ProductVersion: 6.10
Translation: 0x0409 0x04b0

PWS:Win32/Karagany.A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Barys.76750
SkyhighBehavesLike.Win32.Sality.jc
McAfeeGeneric-FABJ!333879035257
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Barys.76750
SangforInfostealer.Win32.Kryptik.Voi1
BitDefenderGen:Variant.Barys.76750
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.VVV
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.5b3168a8
NANO-AntivirusTrojan.Win32.Stealer.ljwpz
AvastWin32:Evo-gen [Trj]
RisingTrojan.Dynamer!8.3A0 (CLOUD)
EmsisoftGen:Variant.Barys.76750 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.PWS.Stealer.538
ZillyaTrojan.Kryptik.Win32.140405
TrendMicroTROJ_GEN.R002C0DBG24
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.3338790352579338
SophosMal/EncPk-ACL
JiangminTrojan/Generic.qrsk
WebrootW32.Malware.gen
VaristW32/SuspPack.EC.gen!Eldorado
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
MicrosoftPWS:Win32/Karagany.A
XcitiumMalware@#3exv73u8rwosv
ArcabitTrojan.Barys.D12BCE
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.76750
GoogleDetected
VBA32BScope.Trojan.MTA.0661
ALYacGen:Variant.Barys.76750
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DBG24
TencentMalware.Win32.Gencirc.1402bc0f
YandexTrojan.Kryptik!ahDdYM36d0A
IkarusTrojan.Win32.Ransom
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Generic_FABJ.333879035257!tr
BitDefenderThetaGen:NN.ZexaF.36804.PmKfaepzlmci
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Barys

How to remove PWS:Win32/Karagany.A?

PWS:Win32/Karagany.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment