Malware

Win32/PSWTool.SAMInside.AA potentially unsafe (file analysis)

Malware Removal

The Win32/PSWTool.SAMInside.AA potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSWTool.SAMInside.AA potentially unsafe virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the lsadump malware family
  • Anomalous binary characteristics

How to determine Win32/PSWTool.SAMInside.AA potentially unsafe?


File Info:

name: 497743B0CD52F0A7FC5F.mlw
path: /opt/CAPEv2/storage/binaries/bcac6197742749e5e548f37be017c6901d80c5541009b3eb939dc87dce2a3a8a
crc32: F538AC2D
md5: 497743b0cd52f0a7fc5f41e08467846f
sha1: a240b8b4d5331f1d4aa32b2add01a190e26287fd
sha256: bcac6197742749e5e548f37be017c6901d80c5541009b3eb939dc87dce2a3a8a
sha512: aad3b774c464d9cf330dba0af498c22bc63e29e07cca724bb56ee71771eebe758ef0d25aa734bc59063f06c9cad8c0e23e72fe58d2b64f5be2bf129631094df7
ssdeep: 12288:1Hs6bJTznB87+8btCRH3PFTCyWwVnylKLTZ3+mP1yBJmc5FJtYJ3gV:1LJobtKH3PywVnylAkJtYJ3g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8D48D027AF1C1B2C6560171CE7797EC22A6FD604F365BC372847F0D6A716C2AA3A365
sha3_384: 325e54a96e8e94738e6c97f3959fd61269ae60ae82d64908d5097780178cc56723abc096b59f0194adec3977a933da60
ep_bytes: 6a6064ff3500000000669c518d4c755b
timestamp: 2011-06-04 14:20:11

Version Info:

Comments: www.InsidePro.com
CompanyName: InsidePro Software
FileDescription: SAMInside
FileVersion: 2.6.6.0
InternalName: SAMInside
LegalCopyright: (c) 2002-2011 InsidePro Software
OriginalFilename: SAMInside.exe
ProductVersion: 2.6.6.0
Translation: 0x0409 0x04b0

Win32/PSWTool.SAMInside.AA potentially unsafe also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Saminside.4!c
FireEyeGeneric.mg.497743b0cd52f0a7
CylanceUnsafe
VIPREPSWTool.Win32.SAMInside
K7AntiVirusUnwanted-Program ( 004ccacc1 )
K7GWUnwanted-Program ( 004ccacc1 )
Cybereasonmalicious.4d5331
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSWTool.SAMInside.AA potentially unsafe
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:PSWTool.Win32.SAMInside.vly
NANO-AntivirusTrojan.Win32.Ool.drkstb
SUPERAntiSpywareHack.Tool/Gen-SAMInside
AvastWin32:Malware-gen
SophosGeneric PUA KC (PUA)
BaiduWin32.Virus.Polip.a
ZillyaTool.SAMInside.Win32.62
McAfee-GW-EditionBehavesLike.Win32.Infected.jh
Ikarusnot-a-virus:PSWTool.Win32.SAMInside
GDataWin32.Trojan.Agent.DNH9G5
Antiy-AVLRiskWare[PSWTool]/Win32.SAMInside
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.PWS.C4807921
McAfeeRDN/Generic PWS.y
MalwarebytesPUP.Optional.SAMInside
TrendMicro-HouseCallTROJ_GEN.R002H06L321
RisingTrojan.Generic@ML.80 (RDML:sJR08sseS4pnZbM3uqBIww)
SentinelOneStatic AI – Malicious PE
FortinetRiskware/SAMInside
AVGWin32:Malware-gen

How to remove Win32/PSWTool.SAMInside.AA potentially unsafe?

Win32/PSWTool.SAMInside.AA potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment