Malware

PWS:Win32/Tibia.BP removal tips

Malware Removal

The PWS:Win32/Tibia.BP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Tibia.BP virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine PWS:Win32/Tibia.BP?


File Info:

crc32: 1CE3E133
md5: e4abf2da2260375fcfbb3f3a5a343a82
name: E4ABF2DA2260375FCFBB3F3A5A343A82.mlw
sha1: 0410f5b48bcc224005ddb3bf2d719603ffc2e9b0
sha256: 7d0eddaecf8d926e8dbed57ac545ad93ab00e3a680f9404a1a15455367499448
sha512: 8a4ad8d7c9bbbaad90056d6b5f7f9ef7a84be6d719410636c3838193f1aef57c4a9d38901b86c70b453b949173066e08d1820cb4be24cba366b6fec8639f5959
ssdeep: 12288:kGz5971uu6q99/KqkNwdJ+0bAbRNNcd09dajXqShJaRuBcSc49onVY847JgUONv:/99SqKwd7AZAVWYBcSb9kVF4F2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Tibia.BP also known as:

BkavW32.AIDetect.malware2
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen2.24715
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.316962
CylanceUnsafe
ZillyaTrojan.Cossta.Win32.3210
AlibabaTrojanPSW:Win32/Tibia.38e4b7df
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.a22603
CyrenW32/Trojan.CJLN-3703
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Tibia.NDS
APEXMalicious
AvastWin32:Tibia-FM [Trj]
ClamAVWin.Trojan.Cossta-197
KasperskyTrojan.Win32.Cossta.nce
BitDefenderGen:Variant.Zusy.316962
NANO-AntivirusTrojan.Win32.Cossta.bygtq
MicroWorld-eScanGen:Variant.Zusy.316962
TencentMalware.Win32.Gencirc.10c394aa
Ad-AwareGen:Variant.Zusy.316962
ComodoTrojWare.Win32.Cossta.~NCE@38tnlu
BitDefenderThetaGen:NN.ZelphiF.34608.YOW@aql0bzni
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_TIBIA.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.e4abf2da2260375f
EmsisoftGen:Variant.Zusy.316962 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Cossta.cig
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1112113
KingsoftWin32.Troj.Cossta.(kcloud)
MicrosoftPWS:Win32/Tibia.BP
ArcabitTrojan.Zusy.D4D622
AegisLabTrojan.Win32.Cossta.4!c
ZoneAlarmTrojan.Win32.Cossta.nce
GDataGen:Variant.Zusy.316962
AhnLab-V3Trojan/Win32.Cossta.C86036
McAfeeGenericR-CRM!E4ABF2DA2260
MAXmalware (ai score=97)
VBA32TScope.Trojan.Delf
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_TIBIA.SMA
RisingTrojan.Generic@ML.97 (RDMK:lAi1+S8aOmOlWO+Uu6u/qQ)
YandexTrojan.GenAsa!tg/oofskdYA
IkarusTrojan-PWS.Win32.Tibia
FortinetW32/Cossta.NDS!tr
AVGWin32:Tibia-FM [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.FRS.HwUBEpsA

How to remove PWS:Win32/Tibia.BP?

PWS:Win32/Tibia.BP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment