Malware

PWS:MSIL/MassLogger!MTB (file analysis)

Malware Removal

The PWS:MSIL/MassLogger!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/MassLogger!MTB virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:MSIL/MassLogger!MTB?


File Info:

crc32: 81EE1510
md5: 7b1f3b2a2ff3e41d10b479d9bb95a811
name: 7B1F3B2A2FF3E41D10B479D9BB95A811.mlw
sha1: 79810af2372ba021e01a1dd3fe3ea7522716a7a1
sha256: d911572c2fce9e45ecf07feb9b4d407a06f0993fad6d2d9f533d06a99ba79b66
sha512: 1aa5e598e78722693928ffd1ff450877d1b3ee8d3714081472e685d97d3f2ea7ffba4b2efc9063eb285e2d1bab7ea5186589c1ee16d9621761ac74a5bf919ad0
ssdeep: 1536:zJmK7KZ7gjyMyaIlfyxFXqlbGrpcQ6WTguKmbE2bl6qbr/5u+C5r5imqVl:zdKuyMmlbGrpB6WTguxb5jb75unqN
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Police.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Police.exe

PWS:MSIL/MassLogger!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.38991
MicroWorld-eScanGen:Variant.Razy.772509
FireEyeGeneric.mg.7b1f3b2a2ff3e41d
CAT-QuickHealTrojan.MsilFC.S17036455
ALYacGen:Variant.Razy.772509
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Stealer.l!c
SangforMalware
K7AntiVirusTrojan ( 0056879b1 )
BitDefenderGen:Variant.Razy.772509
K7GWTrojan ( 0056879b1 )
BitDefenderThetaGen:NN.ZemsilF.34700.im0@aiP5CEn
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWStealer-V [Trj]
ClamAVWin.Malware.Razy-9806344-0
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
AlibabaTrojanSpy:MSIL/Stealer.9c1be9ce
RisingStealer.Agent!1.B723 (CLASSIC)
Ad-AwareGen:Variant.Razy.772509
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.vmqzo
ZillyaTrojan.Agent.Win32.1511054
TrendMicroTROJ_GEN.R002C0GJS20
McAfee-GW-EditionGenericRXMK-NS!7B1F3B2A2FF3
EmsisoftGen:Variant.Razy.772509 (B)
IkarusTrojan.MSIL.Spy
AviraTR/Spy.Agent.vmqzo
MicrosoftPWS:MSIL/MassLogger!MTB
ArcabitTrojan.Razy.DBC99D
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
GDataGen:Variant.Razy.772509
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.C4207833
McAfeeGenericRXMK-NS!7B1F3B2A2FF3
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.RedLineStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.CZE
TrendMicro-HouseCallTROJ_GEN.R002C0GJS20
TencentMalware.Win32.Gencirc.11b099f2
YandexTrojanSpy.Agent!5wCAygvjt7g
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Agent.CZE!tr
AVGWin32:PWStealer-V [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Spy.67f

How to remove PWS:MSIL/MassLogger!MTB?

PWS:MSIL/MassLogger!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment