Trojan

TrojanPSW.Growtopia information

Malware Removal

The TrojanPSW.Growtopia is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPSW.Growtopia virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to modify UAC prompt behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanPSW.Growtopia?


File Info:

crc32: D8F46E95
md5: 7754ec7c538187af0518041468c6dd63
name: 7754EC7C538187AF0518041468C6DD63.mlw
sha1: 4f58a4103358c121e46144ba149f5fc03be710aa
sha256: 1081b399fd1d7fb986d2bb2d1281b0395be8262ae08bda5bc96fbbb3720afac5
sha512: 96f7e4aec4ba3e16dfa726f18e865ec2744a749b111acaa857f5393f34c220faf042b9ec5e6528bbcf5e8597ace520fb35f5d34bba1c07ca549e32df81cc9e3b
ssdeep: 98304:qy0qSyt8i90CVMKlAkNDWFnicQdKCBRhYrVK1jTmFVy2SxNEld9fjVZC/P42RLY:q/yhVMWAGHRBG6sU2ONEeqANIRqM
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

ProgramID:
ProductName:
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0409 0x04e4

TrojanPSW.Growtopia also known as:

K7AntiVirusPassword-Stealer ( 0058006d1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Growtopia.57
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.711773
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWPassword-Stealer ( 0058006d1 )
Cybereasonmalicious.c53818
CyrenW32/Growtopia.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Growtopia.U
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-GameThief.Win32.Worgtop.gen
BitDefenderGen:Variant.Razy.711773
MicroWorld-eScanGen:Variant.Razy.711773
TencentWin32.Trojan-psw.Growtopia.Aheq
Ad-AwareGen:Variant.Razy.711773
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1135125
BitDefenderThetaGen:NN.ZexaF.34266.@pKfauhUUAli
TrendMicroTROJ_GEN.R002C0PKD21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7754ec7c538187af
EmsisoftGen:Variant.Razy.711773 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Worgtop.aa
AviraHEUR/AGEN.1135125
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan[PSW]/Win32.Growtopia
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Razy.DADC5D
GDataWin32.Trojan.GrowtopiaStealer.A
McAfeeArtemis!7754EC7C5381
MAXmalware (ai score=85)
VBA32TrojanPSW.Growtopia
MalwarebytesSpyware.PasswordStealer.Growtopia
TrendMicro-HouseCallTROJ_GEN.R002C0PKD21
YandexTrojan.PWS.Growtopia!3qJ4BQv/rzc
IkarusTrojan-PSW.Growtopia
FortinetW32/Growtopia.I!tr.pws
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove TrojanPSW.Growtopia?

TrojanPSW.Growtopia removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment