Malware

MSIL/PSW.Discord.WF (file analysis)

Malware Removal

The MSIL/PSW.Discord.WF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/PSW.Discord.WF virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine MSIL/PSW.Discord.WF?


File Info:

name: 8A6EC4669307E034C2D4.mlw
path: /opt/CAPEv2/storage/binaries/321ccdd0298de8115280673ae70d24b9db16420419bdb6303678cd82305a4214
crc32: 1FB5AF2E
md5: 8a6ec4669307e034c2d4c6495d2e70cd
sha1: c80994d0fbed48eae01774eff88d211ff401415c
sha256: 321ccdd0298de8115280673ae70d24b9db16420419bdb6303678cd82305a4214
sha512: eaeb796874fd7936e0d3c30f49e6f8ac330f5652beaf60ba642c58d38fdbb47423f3cf25c9aa2c9ff4e4755b3b7ac4d902568f161fccfe7a49501d35577a2458
ssdeep: 3072:4f2FStVZsPhFBrmH++lDKXEAoRLsIkXsbAct0CN8J7ID000ww0cTLgcpJLAe4ao4:iyakF8++lDKXEAoRLsIkXsbAct0CN8Jv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFD36D3833ABDA9DCB105D7D9AECD5000E9D2D2D6E509FD844BC35EE833BD89C89A095
sha3_384: adafb7c9d8077c36a81c99600d1e6f8609e90643fc2b0b153035c658a6a8843cfcbf586c3c3380ea13fb064333ed7c64
ep_bytes: ff250020400000000000000000000000
timestamp: 2099-04-20 16:52:56

Version Info:

Translation: 0x0000 0x04b0
CompanyName: wondershare filmoraa
FileDescription: wondershare filmoraa
FileVersion: 1.0.0.0
InternalName: wondershare filmoraa.dll
LegalCopyright:
OriginalFilename: wondershare filmoraa.dll
ProductName: wondershare filmoraa
ProductVersion: 1.0.0
Assembly Version: 1.0.0.0

MSIL/PSW.Discord.WF also known as:

DrWebTrojan.PWS.DiscordNET.14
MicroWorld-eScanIL:Trojan.MSILZilla.6433
FireEyeIL:Trojan.MSILZilla.6433
ALYacIL:Trojan.MSILZilla.6433
SangforTrojan.Win32.MSILZilla.6433
K7AntiVirusPassword-Stealer ( 0057cc0e1 )
AlibabaTrojanPSW:MSIL/Disco.fe3aa53c
K7GWPassword-Stealer ( 0057cc0e1 )
BitDefenderThetaGen:NN.ZemsilCO.34182.im0@aOiAv2c
CyrenW32/Trojan.VJLT-8365
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Discord.WF
TrendMicro-HouseCallTROJ_GEN.R03FC0WA822
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
BitDefenderIL:Trojan.MSILZilla.6433
AvastWin32:Trojan-gen
EmsisoftIL:Trojan.MSILZilla.6433 (B)
TrendMicroTROJ_GEN.R03FC0WA822
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1240923
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.3500BBC
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataIL:Trojan.MSILZilla.6433
CynetMalicious (score: 99)
McAfeeArtemis!8A6EC4669307
MalwarebytesSpyware.DiscordStealer.Generic
APEXMalicious
TencentMsil.Trojan.Msilzilla.Ebra
YandexTrojan.PWS.Discord!3kVbR7H2nY0
IkarusTrojan.MSIL.PSW
FortinetMSIL/Discord.WF!tr.pws
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove MSIL/PSW.Discord.WF?

MSIL/PSW.Discord.WF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment