Malware

Win32/PSW.Papras.DU information

Malware Removal

The Win32/PSW.Papras.DU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Papras.DU virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Win32/PSW.Papras.DU?


File Info:

name: A12195A16C97AEDF891A.mlw
path: /opt/CAPEv2/storage/binaries/add8f664c5448b4db839de286bb88783d6080bc3e476bf279be0d2f83195f249
crc32: 5B705EFA
md5: a12195a16c97aedf891afa2f5b3a8cb0
sha1: 7b9864fa77764215152049b99ac3495469b44806
sha256: add8f664c5448b4db839de286bb88783d6080bc3e476bf279be0d2f83195f249
sha512: 2a4222e99ab91c87bc18c79cde4f06a714b3c5f754a4005217f00b02b804b6c0c38297e8b616c60bf25154280dca04eaae5b233011430a45729b4bda2aa33408
ssdeep: 6144:bSy571c9ZsLjAltdUkGC4OjSm2/9KAR+LwHODv:bSM7S9qjA6kH4OjSffR+LFL
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B354123EF6C3D936D4EA56B55A150E267FB2E8187C16CB831BA0560EFC302216C1E67D
sha3_384: 49bb60727f79885dafce48316c2fdc3eda9ba3bef409365bf62d843659b74a2b65c1b319885b8b4bea74e85481efd922
ep_bytes: e951feffff0c558bec83ec0068d72b03
timestamp: 1996-01-22 19:45:32

Version Info:

0: [No Data]

Win32/PSW.Papras.DU also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Bedep.Gen.1
FireEyeGeneric.mg.a12195a16c97aedf
CAT-QuickHealTrojan.Generic.19507
SkyhighBehavesLike.Win32.Generic.dc
McAfeeGenericRXAA-AA!A12195A16C97
Cylanceunsafe
ZillyaTrojan.Papras.Win32.6311
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Vawtrak.174edac3
K7GWBackdoor ( 004c2d481 )
K7AntiVirusBackdoor ( 004c2d481 )
BitDefenderThetaGen:NN.ZedlaF.36744.ru5@ai2c24j
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/PSW.Papras.DU
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Bedep.Gen.1
NANO-AntivirusTrojan.Win32.MlwGen.dkwsta
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Uimw
EmsisoftTrojan.Bedep.Gen.1 (B)
F-SecureHeuristic.HEUR/AGEN.1300802
VIPRETrojan.Bedep.Gen.1
TrendMicroBKDR_VAWTRAK.SM0
Trapminemalicious.moderate.ml.score
SophosMal/Vawtrak-H
IkarusTrojan.Win32.PSW
GDataTrojan.Bedep.Gen.1
JiangminTrojan/Generic.bdlln
GoogleDetected
AviraHEUR/AGEN.1300802
Antiy-AVLTrojan[Backdoor]/Win32.Papras
Kingsoftmalware.kb.a.999
XcitiumMalware@#pmasyvd2237z
ArcabitTrojan.Bedep.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Bulta!rfn
VBA32BScope.TrojanRansom.Reveton
MAXmalware (ai score=82)
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_VAWTRAK.SM0
RisingBackdoor.Vawtrak!8.11D (TFE:1:sMlFBettYjN)
YandexTrojan.PWS.Papras!dMyYxf9DWK8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CVTV!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/PSW.Papras.DU?

Win32/PSW.Papras.DU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment