Malware

Mal/Mercu-A removal tips

Malware Removal

The Mal/Mercu-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Mercu-A virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Mercurial malware family

How to determine Mal/Mercu-A?


File Info:

name: 5FD75606B327CD514F7A.mlw
path: /opt/CAPEv2/storage/binaries/d458d80c67a0aa50c6af2b530622f7ece462ea72a13260085b0d3a946a1b4494
crc32: 9A850C1B
md5: 5fd75606b327cd514f7a839c14b27fda
sha1: 4c7945171fa99b095296a3c76f143c801d2de79a
sha256: d458d80c67a0aa50c6af2b530622f7ece462ea72a13260085b0d3a946a1b4494
sha512: 3ef61d42096fc0273af3853feb91cc089c44393d62566fbe29031e60b6f48fca1f55cf827f06eb96c90922ffec749c260c73c9b1d34d797bb5c64ef9b88f359c
ssdeep: 768:7xLzwXFTBZ6aQpDts+uZ2Ls/TjxKZKfgm3EhNC:7xLzK1QPs2Ls/TVF7E3C
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11713184877EC5609F3FE4BBA6CB255244AB6B4A7AC32DB4E1D94589C0873B808D50F73
sha3_384: 091b1959b532a5b5aa11a039a87f19b59ba155d904759772393992ca25c2452c85733c2008ae37dab77a04142cc416b2
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-07-31 08:20:11

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: output.exe
LegalCopyright:
OriginalFilename: output.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Mal/Mercu-A also known as:

BkavW32.Common.73883FCC
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.28184
ClamAVWin.Packed.Bulz-9868353-0
FireEyeGeneric.mg.5fd75606b327cd51
CAT-QuickHealTrojan.MsilFC.S22016763
McAfeePWS-FDKR!5FD75606B327
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent.Win32.2370043
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00596b901 )
AlibabaTrojanPSW:MSIL/LibeRAT.18aba505
K7GWTrojan ( 00596b901 )
CyrenW32/MSIL_Agent.CPX.gen!Eldorado
SymantecInfostealer
ESET-NOD32a variant of MSIL/PSW.Discord.FC
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderIL:Trojan.MSILZilla.28184
SUPERAntiSpywareTrojan.Agent/Gen-Cerbu
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Agent.wc
EmsisoftTrojan-PSW.Agent (A)
F-SecureHeuristic.HEUR/AGEN.1305503
DrWebTrojan.PWS.DiscordNET.50
VIPREIL:Trojan.MSILZilla.28184
TrendMicroTrojanSpy.MSIL.MERCUGRAB.SMSNQ
McAfee-GW-EditionBehavesLike.Win32.Generic.pm
Trapminemalicious.high.ml.score
SophosMal/Mercu-A
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan-Stealer.AnarchyGrabber.C
AviraHEUR/AGEN.1305503
ArcabitIL:Trojan.MSILZilla.D6E18
ViRobotTrojan.Win.Z.Psw.43008.FZ
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
MicrosoftTrojan:MSIL/LibeRAT.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4511865
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.36348.cm0@aG9c0Gd
ALYacIL:Trojan.MSILZilla.28184
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/GdSda.A
RisingStealer.Mercurial!1.D7B6 (CLASSIC)
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/PSW.4C4A!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Mercu-A?

Mal/Mercu-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment