Malware

What is “PWS:MSIL/Browsstl.GG!MTB”?

Malware Removal

The PWS:MSIL/Browsstl.GG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Browsstl.GG!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs
  • Harvests credentials from local FTP client softwares

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:MSIL/Browsstl.GG!MTB?


File Info:

crc32: 6B703182
md5: a955cf90076ac35f44a5a740a21a501a
name: A955CF90076AC35F44A5A740A21A501A.mlw
sha1: 19fb6a8f983c9038c2478cc15235eb27bf3d8791
sha256: a2ff4309b61c5bd0d2e4bc3526ef2939301c121a2365d46fb3811c2a30c6c347
sha512: 8f7f8c52847992eb669178827d25cde4f2ba5acf52cd322fdc69dae6f278849a72592d4bf31da0285fc00ef42c40a85017b0b9ed83fad36144325f849ae53268
ssdeep: 1536:9FJNt8BodLXMCOyALhANInspVQeDxZAb9YtScoKXs9viKocMB:9bNTcRyAL6N4uXxubI9oE+viKocMB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2021
Assembly Version: 1.0.0.0
InternalName: Project.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
LegalTrademarks:
Comments:
ProductName: Project
ProductVersion: 1.0.0.0
FileDescription: Project
OriginalFilename: Project.exe

PWS:MSIL/Browsstl.GG!MTB also known as:

DrWebTrojan.PWS.StealerNET.74
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderGen:Heur.Ransom.HiddenTears.1
Cybereasonmalicious.0076ac
CyrenW32/Zbot.AQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.RXP
APEXMalicious
MicroWorld-eScanGen:Heur.Ransom.HiddenTears.1
Ad-AwareGen:Heur.Ransom.HiddenTears.1
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34690.fm0@am5mj@n
FireEyeGeneric.mg.a955cf90076ac35f
EmsisoftGen:Heur.Ransom.HiddenTears.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1138205
eGambitUnsafe.AI_Score_99%
MicrosoftPWS:MSIL/Browsstl.GG!MTB
ArcabitTrojan.Ransom.HiddenTears.1
GDataGen:Heur.Ransom.HiddenTears.1
MAXmalware (ai score=88)
RisingStealer.Agent!1.D361 (CLASSIC)
IkarusTrojan.MSIL.PSW

How to remove PWS:MSIL/Browsstl.GG!MTB?

PWS:MSIL/Browsstl.GG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment