Malware

Win32/PSW.Lineage.ZD malicious file

Malware Removal

The Win32/PSW.Lineage.ZD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Lineage.ZD virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/PSW.Lineage.ZD?


File Info:

name: C595EFA6CF81732AB820.mlw
path: /opt/CAPEv2/storage/binaries/77e8d85a95d83a1dfd3059c50fc9ff518f91e201b8461d0ecc8c4c77bc8221ee
crc32: 76D88E3A
md5: c595efa6cf81732ab820a4187a389ad0
sha1: bc98e951dec89e1483f236ae9284c1582db8ed17
sha256: 77e8d85a95d83a1dfd3059c50fc9ff518f91e201b8461d0ecc8c4c77bc8221ee
sha512: 67011e6a6411f04ec736052552cac79e9255f2ea8cb94e1830b58c807111af77d9d5aad2b8a4d5bec1564f89649c940d06ba4b8e727ff642a881e5efd5ae4525
ssdeep: 6144:Q4INTbEMWHkBvYApLhTrKUfdOtvHtKrr4Kdyj7XKUTa8m23d7KJqKWMJcjo+eCyu:oVnWUYcL5YHaI7XHgZQKhJgeCmdwWA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12094F152B5A05A72F463C23145B5B603DFBF66294A23D473DF640EC7ACA36F058E9283
sha3_384: 332ef72d1839c44a431a246cea5b34d3ab2a48ba4a13591e624b061a6d8dbe584332cf113c13dea013d4fe5ac8eaf0f9
ep_bytes: e92b1ffaff5500f9020009003200918d
timestamp: 2006-04-03 13:32:33

Version Info:

0: [No Data]

Win32/PSW.Lineage.ZD also known as:

LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.91464
FireEyeGeneric.mg.c595efa6cf81732a
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeW32/Detnat.b
CylanceUnsafe
VIPREWin32.Detnat.B
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0053e00f1 )
AlibabaWorm:Win32/Detnat.a13ae1dd
K7GWTrojan ( 0053e00f1 )
Cybereasonmalicious.6cf817
BitDefenderThetaAI:FileInfector.3265FE380E
CyrenW32/OnlineGames.AB.gen!Eldorado
SymantecW32.Detnat
tehtrisGeneric.Malware
ESET-NOD32Win32/PSW.Lineage.ZD
TrendMicro-HouseCallPE_DETNAT.A
Paloaltogeneric.ml
ClamAVWin.Worm.Detnat-6717390-0
KasperskyWorm.Win32.Detnat.a
BitDefenderTrojan.GenericKDZ.91464
NANO-AntivirusVirus.Win32.Gen.ccmw
CynetMalicious (score: 100)
AvastWin32:Detnat-BK [Wrm]
RisingWorm.Detnat.gz (CLASSIC)
Ad-AwareTrojan.GenericKDZ.91464
SophosML/PE-A + W32/Detnat-AD
ComodoVirus.Win32.Detnat.A0@1n8q5w
DrWebWin32.Liage.2
ZillyaWorm.Detnat.Win32.1339
TrendMicroPE_DETNAT.A
McAfee-GW-EditionBehavesLike.Win32.VirRansom.gc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.91464 (B)
APEXMalicious
AviraW32/Detnat.G
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.25E9
MicrosoftVirus:Win32/Detnat.B
ViRobotWin32.Detnat.B
GDataTrojan.GenericKDZ.91464
GoogleDetected
AhnLab-V3Win32/Detnat
VBA32BScope.Trojan.SvcHorse.01643
ALYacWin32.Detnat.B
MalwarebytesMalware.AI.741399940
TencentMalware.Win32.Gencirc.10b0d300
YandexTrojan.GenAsa!efi7HzNbPUg
IkarusVirus.Win32.Detnat.b
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Detnat.A
AVGWin32:Detnat-BK [Wrm]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.Lineage.ZD?

Win32/PSW.Lineage.ZD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment