Malware

Win32/PSW.Gamania.NFM malicious file

Malware Removal

The Win32/PSW.Gamania.NFM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Gamania.NFM virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/PSW.Gamania.NFM?


File Info:

name: 411B694EEE5E9D1E5327.mlw
path: /opt/CAPEv2/storage/binaries/d19a6075e12445fd5c08d482b9b98506c04e55b1be0db6fff819fec0338381bf
crc32: C3643364
md5: 411b694eee5e9d1e53276981234e275a
sha1: 72ca62fe15c17f0415e7f90fec0ba4ac20e5606d
sha256: d19a6075e12445fd5c08d482b9b98506c04e55b1be0db6fff819fec0338381bf
sha512: 25e1c6e0438f4f7d267aad518a06f2f21d22613ec3ba555b5d64a306d7cf40b5bae09c6df254b822f703bc27b57d0843e575c6d77ab0c69e8ed0a66f043065f5
ssdeep: 768:n79YXg3/SfsHdDMwIXO+VFLGMIscNOK8F8ANo7oVu1G8G1zeHzE4/GuuE:n7Wg3/SudDMwo0MzYONqoYG87L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDF2D045BC0B3499DD8CF7704886F3E98C25E89D27401E198AFD2D13C6A06C47EE69AE
sha3_384: ee4e816216c9c8ebad941e3de8b3963ccc024640bb7e940908e3ec0c09ffc3abdb2115d3130ca87c40151d151e68a788
ep_bytes: b8aa924000ffe068e48a4000750633c0
timestamp: 2006-08-10 12:20:07

Version Info:

0: [No Data]

Win32/PSW.Gamania.NFM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Magania.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.cmW@VgqhNie
FireEyeGeneric.mg.411b694eee5e9d1e
SkyhighBehavesLike.Win32.VirRansom.nc
ALYacGen:Trojan.Heur.cmW@VgqhNie
Cylanceunsafe
VIPREGen:Trojan.Heur.cmW@VgqhNie
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00004eab1 )
AlibabaTrojanPSW:Win32/Magania.4702d37c
K7GWTrojan ( 00004eab1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Gamania.NFM
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.cmW@VgqhNie
NANO-AntivirusTrojan.Win32.Magania.cwnndi
AvastWin32:Evo-gen [Trj]
TACHYONTrojan-PWS/W32.WebGame.36352.Z
SophosMal/Behav-204
F-SecureTrojan-PSW:W32/Magania.gen!B
DrWebTrojan.DownLoader6.22277
ZillyaTrojan.Magania.Win32.45937
TrendMicroMal_OLGM-26
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.cmW@VgqhNie (B)
IkarusTrojan-GameThief.Win32.Magania
JiangminTrojan.Generic.llza
WebrootW32.Trojan.Gen
VaristW32/OnlineGames.BC.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[GameThief]/Win32.Magania
KingsoftWin32.Trojan.Generic.a
MicrosoftPWS:Win32/Magania.gen
XcitiumMalware@#kkdrvzhu0eyf
ArcabitTrojan.Heur.EEA04E
ViRobotTrojan.Win32.PSWMagania.36352.F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.cmW@VgqhNie
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.R1983
McAfeePWS-Gamania.gen.e
MAXmalware (ai score=100)
VBA32BScope.Trojan.Inject
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Downloader.XIR
TrendMicro-HouseCallMal_OLGM-26
RisingTrojan.PSW.Win32.Magania.md (CLASSIC)
YandexTrojan.GenAsa!TuAOSxRvhIU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2035032.susgen
FortinetW32/Gamania.NBR!tr.pws
BitDefenderThetaAI:Packer.499B42611B
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.e15c17
DeepInstinctMALICIOUS

How to remove Win32/PSW.Gamania.NFM?

Win32/PSW.Gamania.NFM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment