Trojan

How to remove “Trojan-PSW.Win32.Pycoon”?

Malware Removal

The Trojan-PSW.Win32.Pycoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Pycoon virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-PSW.Win32.Pycoon?


File Info:

name: 04515EB3FE9B39F68BF0.mlw
path: /opt/CAPEv2/storage/binaries/2d5bf379d9363983145cde78e3f1c6a4c5b4dacf0ba9c46455cfe640ca7180bb
crc32: 847F3F16
md5: 04515eb3fe9b39f68bf04c618b5b67c4
sha1: 617fb5db4fb217b8af072e5f657e2d339f8a9612
sha256: 2d5bf379d9363983145cde78e3f1c6a4c5b4dacf0ba9c46455cfe640ca7180bb
sha512: def55d970659c226163ee33a5e70e2270bed8fc125ab566b38fac1135d856da1aa3f3c47429fae7ea634a3964cefa6913682f179a414159c21ad43e6cbdbc7b7
ssdeep: 49152:j3dUZTHhLAleiUtytyc6qs17zLUcM5Z4:j3dUZFN3tytycPs17zYZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F950227F7528437D1332E3C4C3B5398986EBE201D35A4477AE61E4D9EB8684392E2D7
sha3_384: b1aab9e008e1e52095d930db54f26dfad7bf27fda905926129038864d74c7ce056facdab9195db96615986d27f358043
ep_bytes: 558becb9080000006a006a004975f9b8
timestamp: 2021-04-28 18:29:01

Version Info:

CompanyName: 178网游工作室
FileDescription: 商业程序
InternalName: LoginTools.exe
LegalCopyright: 版权所有 (C) 2010
OriginalFilename: LoginTools.exe
ProductName: 商业程序
ProductVersion: 1, 0, 0, 0
FileVersion: 1,0,0,0
Translation: 0x0804 0x03a8

Trojan-PSW.Win32.Pycoon also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.17992
ClamAVWin.Malware.Bulz-9957991-0
CAT-QuickHealPUA.IgenericIH.S28654578
ALYacGen:Variant.Doina.17992
MalwarebytesRiskWare.GameTool
VIPREGen:Variant.Doina.17992
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 005439d61 )
AlibabaMalware:Win32/km_2ebce5.None
K7GWRiskware ( 005439d61 )
Cybereasonmalicious.3fe9b3
CyrenW32/Legendmir.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.GameTool.S
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Pycoon.gen
BitDefenderGen:Variant.Doina.17992
NANO-AntivirusTrojan.Win32.GameTool.jowqyh
AvastWin32:Evo-gen [Trj]
TencentRiskware.Win32.Gametool.16000348
EmsisoftGen:Variant.Doina.17992 (B)
F-SecureHeuristic.HEUR/AGEN.1324621
DrWebTrojan.DownLoader43.50063
ZillyaTool.GameTool.Win32.1239
TrendMicroTROJ_GEN.R03AC0PFC23
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.04515eb3fe9b39f6
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1CDAB8M
JiangminTrojan.PSW.Pycoon.aa
AviraHEUR/AGEN.1324621
MAXmalware (ai score=87)
Antiy-AVLTrojan[PSW]/Win32.Lmir
ArcabitTrojan.Doina.D4648
ZoneAlarmHEUR:Trojan-PSW.Win32.Pycoon.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Unwanted/Win32.GameHack.R355518
Acronissuspicious
McAfeeGenericRXGA-BH!04515EB3FE9B
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03AC0PFC23
RisingMalware.Lmir!8.E96A (TFE:4:R81oTA2OgLH)
IkarusTrojan-Spy.Lmir
MaxSecureTrojan.Malware.139140117.susgen
FortinetW32/Lmir.BQT!tr
BitDefenderThetaAI:Packer.C6B1A80219
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-PSW.Win32.Pycoon?

Trojan-PSW.Win32.Pycoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment