Malware

Win32/PSW.Tibia.NEG information

Malware Removal

The Win32/PSW.Tibia.NEG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Tibia.NEG virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/PSW.Tibia.NEG?


File Info:

name: 1979DDE915489117A0A2.mlw
path: /opt/CAPEv2/storage/binaries/4e8e86aff9c886ab54a9db2d77364889a64d213543d021d7499d0b12e72a3f51
crc32: 3856E732
md5: 1979dde915489117a0a228cb0f7df12c
sha1: 9c8968700a1c3ab8f09b8eb23d6069e3e83f02ba
sha256: 4e8e86aff9c886ab54a9db2d77364889a64d213543d021d7499d0b12e72a3f51
sha512: f52a4e2056f8a7f1a8d33995dc0f0db5584e555cb778b98958c7d2b52f33722e4c5f0f93b549f99b05a614f6af7011552c06f90ac23358f7bdd9b83160be64ff
ssdeep: 12288:yU87INZirLT1VpSUhXzUaAJgQzsCbj6ig4u:yUmMZuT1jpxASAl5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129946D26FAD0C433C1A35A7CDC5B97B49C25BE903D2869567BF82D8C9F393813526293
sha3_384: 9808e6f7363809d43bd83b240dd1876597a990a7b2b7273d2878ada4f4ec66f5296fc9a9a0a97b03b418cea19c7aea6c
ep_bytes: 558bec83c4f0b8647b4500e824e6faff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: ..
FileDescription: ..
FileVersion: 1.0.0.0
InternalName: ..
LegalCopyright: ..
LegalTrademarks: ..
OriginalFilename: ..
ProductName: ..
ProductVersion: 1.0.0.0
Comments: ..
Translation: 0x0409 0x04e4

Win32/PSW.Tibia.NEG also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Heur.Mint.SP.Sneaky.1
FireEyeGen:Heur.Mint.SP.Sneaky.1
ALYacGen:Heur.Mint.SP.Sneaky.1
CylanceUnsafe
ZillyaTrojan.Scar.Win32.44247
SangforTrojan.Win32.Scar.duki
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanPSW:Win32/Tibia.3a131b69
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.D014B8AA20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Tibia.NEG
Paloaltogeneric.ml
KasperskyTrojan.Win32.Scar.duki
BitDefenderGen:Heur.Mint.SP.Sneaky.1
NANO-AntivirusTrojan.Win32.Scar.jdejt
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Heur.Mint.SP.Sneaky.1
TACHYONTrojan/W32.DP-Scar.447488.B
SophosMal/GamePSW-C
ComodoSuspicious@#a42vu4nkr8zs
F-SecureHeuristic.HEUR/AGEN.1105444
DrWebTrojan.Click1.39466
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.dx!xbm
SentinelOneStatic AI – Suspicious PE
EmsisoftGen:Heur.Mint.SP.Sneaky.1 (B)
APEXMalicious
GDataGen:Heur.Mint.SP.Sneaky.1
JiangminTrojan/Scar.ahbc
AviraHEUR/AGEN.1105444
Antiy-AVLTrojan/Win32.Scar
KingsoftWin32.Troj.Scar.du.(kcloud)
ArcabitTrojan.Mint.SP.Sneaky.1
MicrosoftTrojan:Win32/Fareit!ml
CynetMalicious (score: 99)
McAfeeGeneric.dx!xbm
MAXmalware (ai score=100)
VBA32suspected of Trojan.Downloader.gen
YandexTrojan.GenAsa!zjI2nr4TG5M
IkarusTrojan.Win32.Scar
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cossta.NCV!tr
Cybereasonmalicious.915489
PandaGeneric Malware

How to remove Win32/PSW.Tibia.NEG?

Win32/PSW.Tibia.NEG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment