Malware

PWS:MSIL/Mercurial.GA!MTB information

Malware Removal

The PWS:MSIL/Mercurial.GA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Mercurial.GA!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine PWS:MSIL/Mercurial.GA!MTB?


File Info:

crc32: 76704758
md5: 94e3550869d6be5f158ef851029667de
name: 94E3550869D6BE5F158EF851029667DE.mlw
sha1: b6a23591872d92f37fc9ace437b8ae3fcc3a4ee8
sha256: 5a3d180322e317494934b726b3d0e9b6d2f562f4223f8ceee8e605b8143ff88a
sha512: d0708c6721aa197b81503a40cb15bf47553639d8fa50bf6d60a96e2ebfa71b53b43d74d26279bf93b7d5a810d256304706cd45c63092ee1f767c2002bbce251c
ssdeep: 768:RTV8gO58/5sWOuZoLzPUqKZKfgm3Ehhh:R+Os5LTpF7Ebh
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: nuker.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: nuker.exe

PWS:MSIL/Mercurial.GA!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.101
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.498769
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.1872d9
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
ESET-NOD32a variant of MSIL/PSW.Agent.SHS
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Bulz-9868353-0
KasperskyHEUR:Trojan-PSW.MSIL.Agent.gen
BitDefenderGen:Variant.Bulz.498769
MicroWorld-eScanGen:Variant.Bulz.498769
Ad-AwareGen:Variant.Bulz.498769
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34770.cm0@aycJzno
McAfee-GW-EditionGenericRXOT-FK!94E3550869D6
FireEyeGeneric.mg.94e3550869d6be5f
EmsisoftGen:Variant.Bulz.498769 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftPWS:MSIL/Mercurial.GA!MTB
ArcabitTrojan.Bulz.D79C51
ZoneAlarmHEUR:Trojan-PSW.MSIL.Disco.gen
GDataGen:Variant.Bulz.498769
AhnLab-V3Trojan/Win.Generic.C4511865
McAfeeGenericRXOT-FK!94E3550869D6
MAXmalware (ai score=89)
MalwarebytesSpyware.DiscordStealer
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.SHS!tr.dldr
AVGWin32:PWSX-gen [Trj]

How to remove PWS:MSIL/Mercurial.GA!MTB?

PWS:MSIL/Mercurial.GA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment