Malware

PWS:MSIL/Dcstl.GC!MTB removal instruction

Malware Removal

The PWS:MSIL/Dcstl.GC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Dcstl.GC!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine PWS:MSIL/Dcstl.GC!MTB?


File Info:

name: E839636104A53E8055EA.mlw
path: /opt/CAPEv2/storage/binaries/274f399bc31818eddf086ae185110b5720dd1c299e50f0c1a5de1e80e6917601
crc32: E8630679
md5: e839636104a53e8055ea2ecf3f234048
sha1: fcc28acc3fa35e6c675172a5d27377fb08660025
sha256: 274f399bc31818eddf086ae185110b5720dd1c299e50f0c1a5de1e80e6917601
sha512: 5099809604ebd216f4fc72fee637bef78a2c8dbb95513587863db5dfa3182ac9d318857cb853926230a6a855cec1d492a68a8d9fc7eed000b3db04c3e04ad5ca
ssdeep: 96:Bcsmt7fxPX49VHhqf0fGSiwWk0HCGYMecGKzNt:BsNxaHhw0f3LWKfs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1C1EA02B3E48B69E0EB47382DB3921047B2EBA15872D78F6CDC510D9D31794DA637B2
sha3_384: bf76b4a63dae5c021e6d40cde9c591508ed658e83cbe62082cf9a476419ed1a25255c08b4adcd8fe866b1d5cab192be1
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-06-18 14:28:20

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: test.exe
LegalCopyright:
OriginalFilename: test.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

PWS:MSIL/Dcstl.GC!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Razy.4!c
DrWebTrojan.PWS.DiscordNET.5
MicroWorld-eScanIL:Trojan.MSILZilla.13338
SkyhighGenericRXKD-JW!E839636104A5
McAfeeGenericRXKD-JW!E839636104A5
MalwarebytesGeneric.Malware/Suspicious
VIPREIL:Trojan.MSILZilla.13338
SangforTrojan.MSIL.Discord.CI
K7AntiVirusPassword-Stealer ( 0055ba9b1 )
AlibabaTrojanPSW:MSIL/Dcstl.d26a4ce0
K7GWPassword-Stealer ( 0055ba9b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36802.am0@a0qDXtm
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/PSW.Discord.CI
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderIL:Trojan.MSILZilla.13338
NANO-AntivirusTrojan.Win32.Discord.hljeqa
TencentMsil.Trojan-QQPass.QQRob.Jtgl
EmsisoftIL:Trojan.MSILZilla.13338 (B)
F-SecureHeuristic.HEUR/AGEN.1357629
ZillyaTrojan.Discord.Win32.2112
FireEyeGeneric.mg.e839636104a53e80
SophosMal/Generic-S
IkarusTrojan.MSIL.PSW
GoogleDetected
AviraHEUR/AGEN.1357629
Antiy-AVLTrojan[PSW]/MSIL.Discord
Kingsoftmalware.kb.c.990
MicrosoftPWS:MSIL/Dcstl.GC!MTB
XcitiumMalware@#w8aqm0ru0lf2
ArcabitIL:Trojan.MSILZilla.D341A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
GDataIL:Trojan.MSILZilla.13338
AhnLab-V3Malware/Win32.RL_Generic.C3582529
ALYacIL:Trojan.MSILZilla.13338
Cylanceunsafe
PandaTrj/GdSda.A
RisingStealer.Discord!8.10A86 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Discord.CI!tr.pws
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[stealer]:MSIL/Discord.CI

How to remove PWS:MSIL/Dcstl.GC!MTB?

PWS:MSIL/Dcstl.GC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment