Malware

PWS:MSIL/Cyborg.A removal tips

Malware Removal

The PWS:MSIL/Cyborg.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Cyborg.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
smtp.gmail.com

How to determine PWS:MSIL/Cyborg.A?


File Info:

crc32: 54A7F55C
md5: 7ecf2349918dfbb495891382f32ac7fa
name: chrome.exe
sha1: 9b95f6d33d5408851258bab6c19668da15497a83
sha256: 9f02f15ec7dc00e7aa17734ebdac97f3821aa4ea9814050d991974db03eb8b85
sha512: 7b2ea83d25844c922826cbdc90044ef13c90d18f260c7f45941499b46e4d44be8efd1028128d10bffd093f195dd267a3a45c71a7417c2537f6769a4a2ad928fe
ssdeep: 768:uU8mAoyK46h9z1SY9DvFdqY7czBYYCKUEqIfrvmC7NBIlTm9FqW:kmAN3U9zkUDvFdDczB9Thqebx7OTk
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9Google Inc. All Rights Reserved.
Assembly Version: 0.0.0.0
InternalName: chrome.exe
FileVersion: 23.0.1271.90.
CompanyName: Google Inc.,
LegalTrademarks: Google Chrome
Comments: Google Chrome
ProductVersion: 23.0.1271.90.
FileDescription: Google Chrome
OriginalFilename: chrome.exe

PWS:MSIL/Cyborg.A also known as:

MicroWorld-eScanTrojan.GenericKD.33365558
McAfeePUP-XDM-PR
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderTrojan.GenericKD.33365558
K7GWTrojan ( 700000121 )
Cybereasonmalicious.9918df
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34090.mm0@aWb70Uj
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33365558
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaTrojanPSW:MSIL/Cyborg.d6415764
NANO-AntivirusTrojan.Win32.Agent.dzvpjo
AegisLabTrojan.Win32.Agent.4!c
RisingTrojan.MSIL.KeyLogger!1.647D (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33365558 (B)
F-SecureTrojan.TR/Spy.Gen
TrendMicroTSPY_CYLOG.SM
McAfee-GW-EditionPUP-XDM-PR
MaxSecureTrojan.Malware.771626.susgen
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7ecf2349918dfbb4
SophosMal/Generic-S
IkarusTrojan-Spy
CyrenW32/Trojan.EITI-3959
JiangminTrojan.Agent.cpcl
WebrootW32.Passfox.Heur
AviraTR/Spy.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Agent
MicrosoftPWS:MSIL/Cyborg.A
ArcabitTrojan.Generic.D1FD1E36
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
AhnLab-V3PUP/Win32.RL_Generic.C3575126
Acronissuspicious
ALYacTrojan.GenericKD.33365558
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.Agent
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.AHO
TrendMicro-HouseCallTSPY_CYLOG.SM
TencentWin32.Trojan.Spy.Ammx
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Generic.DN.3CBF3!tr
Ad-AwareTrojan.GenericKD.33365558
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.74b

How to remove PWS:MSIL/Cyborg.A?

PWS:MSIL/Cyborg.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment