Malware

Should I remove “Win32/PSW.Tibia.NJT”?

Malware Removal

The Win32/PSW.Tibia.NJT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Tibia.NJT virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/PSW.Tibia.NJT?


File Info:

name: E4A8E6C8B5AC8AB08CEF.mlw
path: /opt/CAPEv2/storage/binaries/64f4b0f5d7d4f9b62e828da1342af2d5bd810aae93e3d8b0510d64b468415212
crc32: BD9BE22F
md5: e4a8e6c8b5ac8ab08cef8e4e16da2d3c
sha1: 72f4dd0ad62e638ff47d31b17c1f14741a40650d
sha256: 64f4b0f5d7d4f9b62e828da1342af2d5bd810aae93e3d8b0510d64b468415212
sha512: 91cd9b8370cf90dba59cda6ed288e47d4c2c5b5d567e89ee1abe4137c47d99a60e22cad6e532ef6728126ba12efd45d01294de40131f3b6c825a538110d58b8b
ssdeep: 6144:E7NRl1e7cjuV35CoRzXd3sFJVOZnGYMTvHwRPzQiDAUvVp1EMjGSccisd1K24qnb:ml1e8uVJvXd3GfwhQitpNjnXNdptn99b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197A46E26F5E18437D1332A7D9D1B93ECA826BD103D38A8867BE85D4C5F39381792B193
sha3_384: f1a693c07ab9cc36a65ef08caf62980a1c752199ef0fedcbd8de821715fc7fa32b8809656cd12ac3724a3b6316ea12a0
ep_bytes: 558bec83c4f0b830f64500e8006bfaff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/PSW.Tibia.NJT also known as:

MicroWorld-eScanTrojan.GenericKD.67164935
McAfeeArtemis!E4A8E6C8B5AC
MalwarebytesSpyware.PasswordStealer
ZillyaTrojan.Magania.Win32.65714
SangforInfostealer.Win32.Tibia.V820
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanPSW:Win32/Magania.138bccc2
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.8b5ac8
BitDefenderThetaGen:NN.ZelphiF.36196.CGW@aWVdFRe
VirITTrojan.Win32.Generic.YRK
CyrenW32/Tibia.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Tibia.NJT
APEXMalicious
KasperskyTrojan-GameThief.Win32.Magania.ithg
BitDefenderTrojan.GenericKD.67164935
NANO-AntivirusTrojan.Win32.Symmi.cszijq
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.1150ff35
EmsisoftTrojan.GenericKD.67164935 (B)
F-SecureHeuristic.HEUR/AGEN.1331298
VIPRETrojan.GenericKD.67164935
TrendMicroTROJ_GEN.R002C0GEM23
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.e4a8e6c8b5ac8ab0
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.67164935
GoogleDetected
AviraHEUR/AGEN.1331298
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.SGeneric
XcitiumMalware@#1k56ic6f56fil
ArcabitTrojan.Generic.D400DB07
ZoneAlarmTrojan-GameThief.Win32.Magania.ithg
MicrosoftTrojan:JS/Dursg.J
CynetMalicious (score: 100)
VBA32TrojanPSW.Magania
ALYacTrojan.GenericKD.67164935
TACHYONTrojan-PWS/W32.DP-OnLineGames.459264
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0GEM23
RisingSpyware.Keylogger!8.12F (TFE:3:uQar7UntgfM)
YandexTrojan.PWS.Tibia!D58tRcMbskc
IkarusBehavesLike
FortinetW32/Tibia.NJW!tr.pws
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.Tibia.NJT?

Win32/PSW.Tibia.NJT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment