Trojan

About “Trojan-PSW.Win32.Sopher.b” infection

Malware Removal

The Trojan-PSW.Win32.Sopher.b is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Sopher.b virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-PSW.Win32.Sopher.b?


File Info:

name: 3A83DDFD921625DEA95D.mlw
path: /opt/CAPEv2/storage/binaries/79fa187f60cb9f6e228669feb8cb0d12f113770e5d25bbf236477aafe70f6a45
crc32: 2E7DEAA5
md5: 3a83ddfd921625dea95d12264d7ca4db
sha1: 345e95de3a8a58128ca63cc54005155cf7f0f353
sha256: 79fa187f60cb9f6e228669feb8cb0d12f113770e5d25bbf236477aafe70f6a45
sha512: 6a2c12c31395d4017b54df026558639b4e6fe62c5d0ff9bdac15fe85e147e2c4f63db08a79ab0c43890b7f6e48880e46c9757faf539055fa700565da35e783e6
ssdeep: 98304:6YHKrIY6Vbj9CYZQQGq/uVdowywvrYiRQlQNQAj7rE7mn6eJ+B63u1kQ7aO:IcZVP0DQrRwywtR/N7XA7Uo63u1kQ7aO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB5633223202C913D9712A349CDDEDFAAE508E30AE9E05B375C67CD7F539B5429490BB
sha3_384: e300f80c29b9a8a46456be51522889d2713959c5b0056ab438cf34d0d886fe8b943b19ddf0bbc6768648af565cf4e3c1
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-07-25 00:55:47

Version Info:

FileDescription: Tom Clancy's The Division
FileVersion: 7.0.0.0
LegalCopyright:
Translation: 0x0409 0x0000

Trojan-PSW.Win32.Sopher.b also known as:

LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanGen:Variant.Doina.846
FireEyeGeneric.mg.3a83ddfd921625de
CAT-QuickHealDropper.Jeefo.YY5
ALYacGen:Variant.Doina.846
MalwarebytesRiskWare.HackTool
ZillyaDownloader.Agent.Win32.379772
SangforTrojan.Win32.Drop.Agent
K7AntiVirusUnwanted-Program ( 004ba1a41 )
K7GWUnwanted-Program ( 004ba1a41 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/CheatEngine.C.gen!Eldorado
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Sopher.b
BitDefenderGen:Variant.Doina.846
NANO-AntivirusTrojan.Win32.Stealer.fpwscl
AvastWin32:Trojan-gen
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1304735
DrWebTrojan.MulDrop15.62138
VIPREGen:Variant.Doina.846
TrendMicroTROJ_GEN.R014C0PH722
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.tc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Doina.846 (B)
GDataWin32.Riskware.Hacktool.D
AviraHEUR/AGEN.1304735
Antiy-AVLHackTool[Hoax]/Win32.CheatEngine.a
XcitiumMalware@#1pusg21dt73cg
ArcabitTrojan.Doina.846
ZoneAlarmTrojan-PSW.Win32.Sopher.b
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Pup/Win32.RL_Generic.R263950
Acronissuspicious
McAfeeArtemis!3A83DDFD9216
MAXmalware (ai score=100)
VBA32CIL.HeapOverride.Heur
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R014C0PH722
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL2:vRpUwGuvVjsoMX1tXcRdHw)
YandexHackTool.CheatEngine!h2lP7QG9eRI
IkarusPUA.HackTool.Cheatengine
MaxSecureTrojan.Malware.1207211.susgen
FortinetW32/Agent.CQ!tr
BitDefenderThetaGen:NN.ZemsilF.36250.7v2@a4qVifl
AVGWin32:Trojan-gen
Cybereasonmalicious.d92162
DeepInstinctMALICIOUS

How to remove Trojan-PSW.Win32.Sopher.b?

Trojan-PSW.Win32.Sopher.b removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment