Trojan

What is “Trojan-PSW.Win32.Benfgame”?

Malware Removal

The Trojan-PSW.Win32.Benfgame is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Benfgame virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Trojan-PSW.Win32.Benfgame?


File Info:

name: 285AD1F9C2DD6E847EFD.mlw
path: /opt/CAPEv2/storage/binaries/df943244def25c38c06377204d69073c6484c4babdcb732ab80332c1e76acbf6
crc32: 74AFD8CD
md5: 285ad1f9c2dd6e847efdcc93f65f340d
sha1: 95667374f01f97ca6fc4fa554c41f3188b546158
sha256: df943244def25c38c06377204d69073c6484c4babdcb732ab80332c1e76acbf6
sha512: d097141591091771434f778c87b6aa7261d24a9853260220f59631bc75cdfe7d2354f9614d47a5dd1025089ed391a67d08654f83a34a66d7df0f338bbfb3727c
ssdeep: 6144:53OOCKLlcPKJEld2zJQPfuSlMHyaXXu6FQGkcC+V5R5azYBONNYJGBtFN:FOOZpUtlwX+zc7V5Rn1J2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11FA46D2BB6D08433D2231A7C8C9BC7A99D26BE502E2954463FF96D4C4F7D78139262D3
sha3_384: e190919f8cafb1bc78fd5d2f3c2dd3ce39ad529e2c0854497463d4a0987e2791de98a80a1c09d06304c42a6a538c0511
ep_bytes: c3e9eaa5faffebeb8bc35f5e5b59595d
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-PSW.Win32.Benfgame also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Fasong.l6SH
ClamAVWin.Malware.Fasong-9910797-0
FireEyeGeneric.mg.285ad1f9c2dd6e84
CAT-QuickHealTrojan.Generic.27193
McAfeeArtemis!285AD1F9C2DD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Benfgame.Win32.9
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052964f1 )
AlibabaWorm:Win32/Fasong.485
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.4f01f9
BitDefenderThetaGen:NN.ZexaF.36722.DqY@aac5xDb
CyrenW32/ABRisk.IVAJ-4238
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Benfgame.gen
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Scar.16000123
F-SecureTrojan.TR/Patched.Ren.Gen2
BaiduWin32.Trojan-PSW.OLGames.bm
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusWorm.Win32.Fasong
AviraTR/Patched.Ren.Gen2
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.b.990
ZoneAlarmHEUR:Trojan-PSW.Win32.Benfgame.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CHS23
RisingWorm.Fasong!1.D14C (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetPossibleThreat.RF
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-PSW.Win32.Benfgame?

Trojan-PSW.Win32.Benfgame removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment