Trojan

How to remove “Trojan-PSW.Win32.Phpw”?

Malware Removal

The Trojan-PSW.Win32.Phpw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Phpw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • The following process appear to have been packed with Themida: 3.exe
  • Attempts to identify installed AV products by installation directory
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ip-api.com

How to determine Trojan-PSW.Win32.Phpw?


File Info:

crc32: 181571A8
md5: e259913ffeb4a1b34bda45e12424b609
name: 3.exe
sha1: 5a8edc396c3ddc6796236cb5d14f83dc876c3392
sha256: 5432a57178fbe2052b1d4d66290c9a68a78ca5d6a2ea9f2bcae6b5a8ed7c292f
sha512: fcc393d7af5dddf958567c2ee92be37c5e08a2fe58915791d30208e74f99c66b0824251a32c0088d7074ca5aec05daceafc5cfe67f2c0b14b75170f05fdaa8d5
ssdeep: 49152:6mbOwxbMgrTzzLcCdjzkfnElkEvcIYYFo9VlfH1ac1jhdDpyu4IORBz:txbMyjwecvEaiYYO9JBpbcu4IORB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Phpw also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanTrojan.GenericKD.33493818
Qihoo-360Win32/Trojan.Dropper.838
McAfeeArtemis!E259913FFEB4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.a!c
SangforMalware
K7AntiVirusTrojan ( 0040f4ef1 )
BitDefenderTrojan.GenericKD.33493818
K7GWTrojan ( 0040f4ef1 )
Cybereasonmalicious.96c3dd
TrendMicroTROJ_FRS.0NA103C220
BitDefenderThetaGen:NN.ZexaF.34098.lAWaaCIeEOpi
CyrenW32/Trojan.EQAY-9037
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Malware.GenericStealer.T1W2G9
KasperskyHEUR:Trojan-PSW.Win32.Phpw.gen
AlibabaPacked:Win32/Themida.157f689e
RisingTrojan.Occamy!8.F1CD (CLOUD)
Ad-AwareTrojan.GenericKD.33493818
SophosMal/Generic-S
ComodoMalware@#2t13p6jebrh9m
F-SecureHeuristic.HEUR/AGEN.1045048
ZillyaTrojan.Themida.Win32.9527
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e259913ffeb4a1b3
EmsisoftTrojan.GenericKD.33493818 (B)
SentinelOneDFI – Malicious PE
JiangminTrojanDownloader.Generic.bfoo
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1045048
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FF133A
ZoneAlarmHEUR:Trojan-PSW.Win32.Phpw.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C3545808
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.Agent.Occamy.A
MAXmalware (ai score=86)
MalwarebytesSpyware.PasswordStealer.Themida
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.Themida.HIO
TrendMicro-HouseCallTROJ_FRS.0NA103C220
TencentWin32.Trojan-downloader.Generic.Ahxx
YandexTrojan.Themida!
IkarusTrojan.Win32.Themida
eGambitUnsafe.AI_Score_99%
FortinetW32/Themida.HIO!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Phpw?

Trojan-PSW.Win32.Phpw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment