Trojan

Trojan-PSW.Win32.Kpot information

Malware Removal

The Trojan-PSW.Win32.Kpot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Kpot virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

icaterp.com
iplogger.org
apps.identrust.com

How to determine Trojan-PSW.Win32.Kpot?


File Info:

crc32: CC65C18C
md5: a7e0007c07779855a4c06e81ab0af3dc
name: upload_file
sha1: 9865bf022d7ff4c52076292eb19352392b9dd46c
sha256: e73eb64f139fbfe78f487764bdd6c3a98f2f5383becc3905fbb9ac2a9918a91e
sha512: 974e80cae0e2ca213a7efb7b92705d93f2b3680a567664a5890c9b11de6af28cfcc9cc7b270da208ebe88f6196b6692dcd06ef5aabd0eaf7dbb30c6609098862
ssdeep: 6144:Gl0tKQeWQFrRh3joSP4gVYgxUl9q0xzBuvL61mxCLo1:M0tKQ+LQMYgxUlFxo61G1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Kpot also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34768422
CAT-QuickHealTrojan.Agent
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Kpot.i!c
SangforMalware
K7AntiVirusSpyware ( 00551d0e1 )
BitDefenderTrojan.GenericKD.34768422
K7GWSpyware ( 00551d0e1 )
Cybereasonmalicious.c07779
ArcabitTrojan.Generic.D2128626
TrendMicroTROJ_GEN.R014C0GJH20
CyrenW32/Trojan.ZQIA-2516
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Agent.PTL
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Kpot.gen
AlibabaTrojanSpy:Win32/Redcap.9fd71fe4
RisingTrojan.Generic@ML.92 (RDMK:fM4VIhsNCvsdHwZoLF0QJg)
Ad-AwareTrojan.GenericKD.34768422
EmsisoftTrojan.GenericKD.34768422 (B)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Redcap.dnhpc
DrWebTrojan.PWS.Siggen2.57263
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.a7e0007c07779855
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
JiangminTrojanSpy.AveMaria.dv
WebrootW32.Trojan.Gen
AviraTR/Redcap.dnhpc
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Ymacco.AAE7
ZoneAlarmHEUR:Trojan-PSW.Win32.Kpot.gen
GDataTrojan.GenericKD.34768422
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.GenericKD.34768422
VBA32Trojan.MTA.01011
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0GJH20
TencentWin32.Trojan-qqpass.Qqrob.Lpky
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kpot!tr.pws
BitDefenderThetaGen:NN.ZexaF.34570.puW@a4RLkzhi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.PSW.b97

How to remove Trojan-PSW.Win32.Kpot?

Trojan-PSW.Win32.Kpot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment