Trojan

Trojan:Win32/Primarypass (file analysis)

Malware Removal

The Trojan:Win32/Primarypass is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Primarypass virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Primarypass?


File Info:

name: BEC64C813587F7E6B28D.mlw
path: /opt/CAPEv2/storage/binaries/8f808f011963709b5f9fb905c125384b7cc7736d2ea9e4ca37008250edbb4837
crc32: 3036765A
md5: bec64c813587f7e6b28d4682599e22f0
sha1: d1ce844cc8a0b5ef092f8b02c3e15f7d217687bd
sha256: 8f808f011963709b5f9fb905c125384b7cc7736d2ea9e4ca37008250edbb4837
sha512: fbfe5372ed05759c0d999e9061ab2aa94dbeae76c361d7ad0b6f135f214e382999c4d41df70d8f895a03f561ccf44a87f7f93041f489569b1f40da429ff3712d
ssdeep: 768:EYdtH9fDBjTPfbKGFHiUCaYNdGjAIjNgm6WLCdh1:EYdfwMmN0MKVCdh1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A13E662EFD994B9F4A206B0441E5FF9B57B6465C62F9ECF56808C0C083225CEF36267
sha3_384: b3dadacf7a61856926fa459a3aa8a3ba8898c15afb428da12570cbc57362029f07e963fad4efd71d8a390624aa3e591a
ep_bytes: 693f6fffffff2a0000001b3004003e00
timestamp: 2007-10-06 04:08:19

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft Corporation
FileDescription:
FileVersion: 3.0.4203.835
InternalName: PerformanceCounterInstaller.exe
LegalCopyright: Copyright © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks: Microsoft® is a registered trademark of Microsoft Corporation. Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: PerformanceCounterInstaller.exe
ProductName: Windows Workflow Foundation
ProductVersion: 3.0.4203.835
Assembly Version: 3.0.0.0

Trojan:Win32/Primarypass also known as:

BkavW32.AIDetectMalware.CS
LionicWorm.Win32.Mamianune.mBmR
MicroWorld-eScanGeneric.ServStart.B.A0672E3B
SkyhighBehavesLike.Win32.Infected.pm
McAfeeTrojan-FQGJ!BEC64C813587
Cylanceunsafe
ZillyaDropper.Dinwod.Win32.2338
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Dinwod.ff8d5646
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitGeneric.ServStart.B.A0672E3B
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GOPJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Staser-9938521-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGeneric.ServStart.B.A0672E3B
NANO-AntivirusTrojan.Win32.Crypted.ezgxcy
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Tufik
TencentMalware.Win32.Gencirc.10bdbbaa
SophosMal/Generic-S
F-SecureTrojan.TR/Drop.Dinwod.qeofa
DrWebTrojan.DownLoader6.42919
VIPREGen:Variant.Razy.288221
EmsisoftGeneric.ServStart.B.A0672E3B (B)
SentinelOneStatic AI – Malicious PE
VaristW32/MSIL_Agent.EK.gen!Eldorado
AviraTR/Drop.Dinwod.qeofa
Antiy-AVLGrayWare/MSIL.Ipamor.a
Kingsoftmalware.kb.c.999
XcitiumTrojWare.MSIL.Dinwod.BVI@7xhkvi
MicrosoftTrojan:Win32/Primarypass
ZoneAlarmUDS:Trojan-Dropper.Win32.Dinwod.rsj
GDataGeneric.ServStart.B.A0672E3B
GoogleDetected
AhnLab-V3Trojan/Win32.Dinwod.C2778114
BitDefenderThetaGen:NN.ZexaF.36680.bq0@aCh2ZJdb
MalwarebytesGeneric.Malware.AI.DDS
RisingBackdoor.ServStart!1.B58A (CLASSIC)
IkarusTrojan.Dropper
MaxSecureDropper.Dinwood.rsj
FortinetMSIL/Agent.164E!tr
AVGWin32:Tufik
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Primarypass?

Trojan:Win32/Primarypass removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment