Malware

How to remove “PWS:MSIL/HtmStealer.A!MTB”?

Malware Removal

The PWS:MSIL/HtmStealer.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/HtmStealer.A!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PWS:MSIL/HtmStealer.A!MTB?


File Info:

crc32: 745A7F42
md5: 455e9796cbf5f699e54c418884327edd
name: 455E9796CBF5F699E54C418884327EDD.mlw
sha1: e93b58a4f90131029d96ed505d6a5449aff4e937
sha256: 9132db39ad0e8e1a2e3348728355eb50078d2c8fdf89f114721d88bbe162e77a
sha512: 36391cecd52297dadee6649cad41483ff32713b6c3b88f45b60e7d230e55699a4a55558028dcb772aca2c3fc1482354a72dd1d4f00276faf49758e41d1a4be66
ssdeep: 24576:ap+EiGf1PL1Rp4lzoYf1cmdtObzVJpJ3scp4CqLwD2nuT:qiGf1PPp4lzogcmSVJpibbLwCm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:MSIL/HtmStealer.A!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052ab361 )
LionicRiskware.Win32.Malicious.1!c
Elasticmalicious (high confidence)
DrWebTrojan.DownloaderNET.81
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.44044947
CylanceUnsafe
SangforInfostealer.MSIL.HtmStealer.A!MTB
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanSpy:Win32/Stealer.272f8cc5
K7GWTrojan ( 0052ab361 )
Cybereasonmalicious.6cbf5f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Bladabindi-9862893-0
KasperskyTrojan-Spy.Win32.Stealer.ubu
BitDefenderTrojan.GenericKD.44044947
NANO-AntivirusTrojan.Win32.Stealer.hzmpcx
MicroWorld-eScanTrojan.GenericKD.44044947
TencentWin32.Trojan-spy.Stealer.Pbpm
Ad-AwareTrojan.GenericKD.44044947
SophosMal/Generic-S
ComodoMalware@#79i9scwgcwn3
BitDefenderThetaGen:NN.ZexaF.34266.hzW@ay@x0cm
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DK621
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.455e9796cbf5f699
EmsisoftTrojan.GenericKD.44044947 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137309
MicrosoftPWS:MSIL/HtmStealer.A!MTB
GDataTrojan.GenericKD.44044947
AhnLab-V3Trojan/Win32.Packed.R356085
Acronissuspicious
McAfeeGenericRXHT-JV!455E9796CBF5
MAXmalware (ai score=80)
VBA32Trojan.Tiggre
TrendMicro-HouseCallTROJ_GEN.R002C0DK621
IkarusTrojan.Msil
FortinetRiskware/GenericRXHT
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PWS:MSIL/HtmStealer.A!MTB?

PWS:MSIL/HtmStealer.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment