Malware

PWS:MSIL/Petun.A removal tips

Malware Removal

The PWS:MSIL/Petun.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Petun.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:MSIL/Petun.A?


File Info:

crc32: 4AB91C2F
md5: 82d215a75fb488924bd0b6c9b8eb7c8b
name: 82D215A75FB488924BD0B6C9B8EB7C8B.mlw
sha1: 479d006342c914ffd4bc403572fc0fe81218e4a4
sha256: b09eb23e23e8af6efcef8dcc7124f17a762c740b62410cef160f105d889eaf5f
sha512: ca2704696a293b6c0214ccfc6c1180335e41b8e5fb6f21062d23987ec931bea2205c420dd16609af08c6f884d9a1fbbb323522426e16eb726541ffe3e42a98ff
ssdeep: 768:UhGivbbvmmRmjU0WwDThQ0YxyJbtsJp5JrFFnCiFJzu06rwZ:gXmmRmjU0BDlQlA6p5hFFnCiFp6r8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft
Assembly Version: 1.0.0.0
InternalName: Karma Koin Codes.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription: Karma Koin
OriginalFilename: Karma Koin Codes.exe

PWS:MSIL/Petun.A also known as:

MicroWorld-eScanTrojan.GenericKD.40460664
CAT-QuickHealTrojan.Orsam.A3
Qihoo-360Win32/Trojan.55c
McAfeePWS-Zbot.gen.yg
CylanceUnsafe
VIPRETrojan-PWS.MSIL.Petun.a (v)
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderTrojan.GenericKD.40460664
K7GWTrojan ( 700000121 )
Cybereasonmalicious.75fb48
ArcabitTrojan.Generic.D2696178
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34152.cm0@aeE2WDd
CyrenW32/MSIL_Troj.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.BP
TrendMicro-HouseCallTROJ_GEN.FCBEZHE
ClamAVWin.Packed.Zbot-8176461-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanPSW:MSIL/Petun.5bf9e859
NANO-AntivirusTrojan.Win32.TrjGen.dhbnsn
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.MSIL.KeyLogger!1.647D (CLOUD)
Ad-AwareTrojan.GenericKD.40460664
EmsisoftTrojan.GenericKD.40460664 (B)
ComodoWorm.Win32.KeyLogger.AutoRun.AE@4pfb41
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.Siggen3.14508
ZillyaTrojan.Agent.Win32.770818
TrendMicroTROJ_GEN.FCBEZHE
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.82d215a75fb48892
SophosMal/Agent-ASV
APEXMalicious
F-ProtW32/MSIL_Troj.F.gen!Eldorado
JiangminTrojan/Generic.nxos
WebrootW32.Malware.Gen
AviraTR/Spy.Gen
FortinetMSIL/Kryptik.GBD!tr
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftPWS:MSIL/Petun.A
SUPERAntiSpywareTrojan.Agent/Gen-Petun
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Petun.C123857
ALYacTrojan.GenericKD.40460664
MAXmalware (ai score=100)
VBA32CIL.StupidPInvoker-1.Heur
MalwarebytesTrojan.KeyLogger.MSIL
IkarusTrojan-Spy.Win32.Zbot
PandaGeneric Malware
TencentWin32.Trojan.Spy.Ebgs
YandexTrojan.Agent!fxZ3Ay20Fzo
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataMSIL.Trojan-Spy.Petun.B
AVGMSIL:KeyLogger-AB [Spy]
AvastMSIL:KeyLogger-AB [Spy]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.7164915.susgen

How to remove PWS:MSIL/Petun.A?

PWS:MSIL/Petun.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment