Trojan

Trojanpwszbot.Gsb removal instruction

Malware Removal

The Trojanpwszbot.Gsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojanpwszbot.Gsb virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojanpwszbot.Gsb?


File Info:

name: BA2C90E78535E354CBD7.mlw
path: /opt/CAPEv2/storage/binaries/6e0a3f09691bf3d16ae38992e98ba92927e66d240b10c22de47317ad75c1c488
crc32: F947CEBD
md5: ba2c90e78535e354cbd78feb66011087
sha1: 157356d13595d52c4fc87794b473f0e7959b680d
sha256: 6e0a3f09691bf3d16ae38992e98ba92927e66d240b10c22de47317ad75c1c488
sha512: 293dc91da0e0c18d8e46c3f1c55df76e060e89579a871125789b1f6c5eb43fcac9e410d62aafd4b0d407e8636b6995e85d0ed393cb18fb128035d9c882f4a906
ssdeep: 384:FlF5u+XVNu9/efXYp2N68wfmt5+WVF43mkQ1IdbGJoPnViAp:LPu+XVY9/e/ZZw+t5vVuWT+dqyPoi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C035639DAD844B5E3BBC63E85F651C9D826BD213B016DCE50CA32810933B57ECB11AE
sha3_384: 665fcc56c68df8ddd28d2258ee8a1e09aaf21aa0fffa04019f3c86eac8ba18ddb276decc4dda199c730b2123abad9b28
ep_bytes: 57565351e87ef4ffffc3cccccccccccc
timestamp: 1973-03-03 10:25:35

Version Info:

CompanyName: JineJong
FileDescription: JineJong company
FileVersion: Version 2.5.23
InternalName: JineJong
LegalCopyright: Copyright by JineJong
OriginalFilename: JineJong
Translation: 0x040b 0x04e2

Trojanpwszbot.Gsb also known as:

LionicHacktool.Win32.ArchSMS.kZuA
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.34292
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.ba2c90e78535e354
CAT-QuickHealTrojanpwszbot.Gsb
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Cutwail.bza (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaMalware:Win32/km_24894.None
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.78535e
BitDefenderThetaGen:NN.ZexaF.34114.cq2@a8Vb8fmG
CyrenW32/Upatre.GR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
TrendMicro-HouseCallTROJ_UPATRE.SMBG
Paloaltogeneric.ml
ClamAVWin.Downloader.Upatre-6840800-0
KasperskyTrojan-Downloader.Win32.Upatre.bla
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Upatre.dfecyf
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Agent-AULS [Trj]
TencentMalware.Win32.Gencirc.10b0c5b0
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaDownloader.Upatre.Win32.66076
TrendMicroTROJ_UPATRE.SMBG
McAfee-GW-EditionBehavesLike.Win32.Generic.nt
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-R + Troj/HkMain-AZ
IkarusTrojan.Win32.Bublik
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminTrojanDownloader.Upatre.p
AviraHEUR/AGEN.1135285
Antiy-AVLTrojan/Generic.ASMalwS.BEF522
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Upatre.C2673332
Acronissuspicious
McAfeeUpatre-FAEL!BA2C90E78535
VBA32Trojan.Download
MalwarebytesTrojan.Upatre.Generic
APEXMalicious
RisingDownloader.Waski!8.184 (TFE:dGZlOgIHHEf+jZx7dg)
YandexTrojan.GenAsa!+rIQ7cDoUXQ
MAXmalware (ai score=84)
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojanpwszbot.Gsb?

Trojanpwszbot.Gsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment