Malware

What is “PWS:Win32/Tibia.AS”?

Malware Removal

The PWS:Win32/Tibia.AS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Tibia.AS virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PWS:Win32/Tibia.AS?


File Info:

name: 2053B51C05ECC20D90E6.mlw
path: /opt/CAPEv2/storage/binaries/1fcb13e312540a76faceb91e07bd7d8a518695cf861edf10a1ea26a53498d98d
crc32: F020DB9C
md5: 2053b51c05ecc20d90e6cc3abfb3d774
sha1: 163589cbb35cd2b87460d7b63b3ad121f0df178f
sha256: 1fcb13e312540a76faceb91e07bd7d8a518695cf861edf10a1ea26a53498d98d
sha512: 72e0560d304a32b159d5ed90a5d1a1a389e2c07d30313d6cbeb5e390c6b12e7538ad90eefc2c31b9f2f9430433e223a312e335f4452178e1f5a57e94d8978f6f
ssdeep: 6144:is8XGxZyB1HkoGMHarsCxJpYdraFz65m20bXRVZkgjZIgafIIsjoEFin3ld:t8XcZyB1HkMdraRmN0bHZINQv9in1d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A948E26F6E08833D1A3253DDC1FA768AC39BE913D6459463BF82D4C4F3A7813526297
sha3_384: de1c17ffb787c8d44162c2f8d6e0799f1aadf6940ce5b3071c7afc68cd80770c5b013ad735db8a8917aac1b7812707f8
ep_bytes: 558bec83c4f0b840614500e8c4fafaff
timestamp: 2007-08-04 11:07:18

Version Info:

CompanyName: lopa
FileDescription: lopa
FileVersion: 4.4.4.4
InternalName: lopa
LegalCopyright: lopa
LegalTrademarks: lopa
OriginalFilename: lopa
ProductName: lopa
ProductVersion: 4.4.4.4
Translation: 0x046e 0x04e4

PWS:Win32/Tibia.AS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.zG1@t97qgkoG
FireEyeGeneric.mg.2053b51c05ecc20d
SkyhighGeneric.bop
McAfeeGeneric.bop
VIPREGen:Trojan.Heur.zG1@t97qgkoG
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderGen:Trojan.Heur.zG1@t97qgkoG
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.bb35cd
VirITTrojan.Win32.Generic.AJZC
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Tibia.NEG
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Scar-2929
KasperskyTrojan.Win32.Scar.bevx
AlibabaTrojanPSW:Win32/Tibia.1e75ffd6
NANO-AntivirusTrojan.Win32.Scar.bjpzr
ViRobotTrojan.Win32.Scar.350500
RisingTrojan.Generic@AI.85 (RDML:cZrs3omQRjAg13G1PSIeDA)
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1331138
DrWebTrojan.MulDrop2.64052
ZillyaTrojan.Scar.Win32.11805
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.zG1@t97qgkoG (B)
IkarusTrojan.Win32.Scar
JiangminTrojan/Scar.nxc
WebrootW32.Infostealer.Gen
VaristW32/OnlineGames.DJ.gen!Eldorado
AviraHEUR/AGEN.1331138
Antiy-AVLTrojan/Win32.Scar
KingsoftWin32.HeurC.KVM007.a
MicrosoftPWS:Win32/Tibia.AS
XcitiumTrojWare.Win32.Agent.~JH4@1ohy0k
ArcabitTrojan.Heur.E28D2C
ZoneAlarmTrojan.Win32.Scar.bevx
GDataGen:Trojan.Heur.zG1@t97qgkoG
GoogleDetected
AhnLab-V3Win-Trojan/Scar.417290
BitDefenderThetaAI:Packer.A3265DA51C
ALYacGen:Trojan.Heur.zG1@t97qgkoG
MAXmalware (ai score=98)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Keyloggerger
Cylanceunsafe
PandaGeneric Malware
TencentMalware.Win32.Gencirc.13b37d7a
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.921714.susgen
AVGWin32:Scar-DA [Trj]
AvastWin32:Scar-DA [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PWS:Win32/Tibia.AS?

PWS:Win32/Tibia.AS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment