Malware

PWS:MSIL/Discord.DHC!MTB (file analysis)

Malware Removal

The PWS:MSIL/Discord.DHC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Discord.DHC!MTB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine PWS:MSIL/Discord.DHC!MTB?


File Info:

crc32: FD986A74
md5: a140d77be302f7cfe2a5d7a06e907ab2
name: snake.exe
sha1: ceebc66055ea928b6e5a9fac4cec439db2255314
sha256: f2add7b46394cf5312d91dc7c3ea3e85abe7e0152eb8403c07c758233bb9540d
sha512: ea1fbc39b0e25505b6a75c68b3cde5a638b5076389f353ad9787fff5d0c54fcdc090a4b13219f7753cf16490aa43ad9aac168d764881a0e9f05671e4c1c85f74
ssdeep: 192:+6SUaIoYFZcKMhZOdyo58+UqWenjfFhLS1:+6SnIoYE7kEo58+UqWwNhL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 0.0.0.1
InternalName: Assembly title
FileVersion: 0.0.0.1
CompanyName:
Title: Assembly title
LegalTrademarks:
Comments:
ProductName: Assembly product name
ProductVersion: 1.0.0.0
FileDescription: Assembly title
OriginalFilename: Assembly title

PWS:MSIL/Discord.DHC!MTB also known as:

MicroWorld-eScanGen:Variant.Razy.461180
FireEyeGeneric.mg.a140d77be302f7cf
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Razy.461180
MalwarebytesTrojan.DiscordStealer
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.461180
K7GWTrojan ( 700000121 )
Cybereasonmalicious.be302f
TrendMicroTrojanSpy.MSIL.DISCHOARD.SM
BitDefenderThetaGen:NN.ZemsilF.31988.am0@am5nQVh
F-ProtW32/Razy.CN.gen!Eldorado
ESET-NOD32a variant of MSIL/PSW.Discord.AP
TrendMicro-HouseCallTrojanSpy.MSIL.DISCHOARD.SM
AvastWin32:PWSX-gen [Trj]
GDataMSIL.Trojan-Stealer.Dhaxx.A
KasperskyHEUR:Trojan-PSW.MSIL.Agent.gen
AlibabaPWSteal:MSIL/Discord.2a303ee1
RisingStealer.Discord!1.B7AA (CLASSIC)
Ad-AwareGen:Variant.Razy.461180
SophosMal/Disteal-B
ComodoTrojWare.MSIL.PSW.Discord.AP@8g3b3c
F-SecureHeuristic.HEUR/AGEN.1041225
DrWebTrojan.PWS.Stealer.25724
Invinceaheuristic
EmsisoftGen:Variant.Razy.461180 (B)
CyrenW32/Razy.CN.gen!Eldorado
JiangminTrojan.PSW.MSIL.gah
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1041225
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/MSIL.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D7097C
AhnLab-V3Malware/Win32.RL_Generic.R263796
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agent.gen
MicrosoftPWS:MSIL/Discord.DHC!MTB
McAfeePWS-FCML!A140D77BE302
VBA32TScope.Trojan.MSIL
CylanceUnsafe
IkarusTrojan.MSIL.PSW
FortinetMSIL/Agent.RCF!tr.pws
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove PWS:MSIL/Discord.DHC!MTB?

PWS:MSIL/Discord.DHC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment