Malware

PWS:MSIL/Stealer.DHB!MTB malicious file

Malware Removal

The PWS:MSIL/Stealer.DHB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Stealer.DHB!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine PWS:MSIL/Stealer.DHB!MTB?


File Info:

name: 3521025207AC71C00C77.mlw
path: /opt/CAPEv2/storage/binaries/e90e7989a41fb85271b9466ad90c8e62357a2347c3b930e3e81a1818d1b80a2a
crc32: 8ABE3886
md5: 3521025207ac71c00c778079aa4fef58
sha1: a8e127093a5ce5b93c8edb9d5739f458cb9b45ab
sha256: e90e7989a41fb85271b9466ad90c8e62357a2347c3b930e3e81a1818d1b80a2a
sha512: d5db907360da95ca3a657e89bbdcff270105de1999a36f8bfa79e6a3ec91e48ee4aaab6f7e55d4bcd4713b53f76afd46525193b11ae212d02f3bd1e0480f1b09
ssdeep: 96:8k2mZZ3qSQ6EGFzpLHP9XMQ00Ws6TMG20+O0k92YWdqUE7BizNt:i6EGN1P9XTeTMGIjuE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193D1B621B3EC5736EE7A8F798CA3A34022B5F7616513CF5E68D4018E5C117658A71AA0
sha3_384: 25bce9b27e90def431673a658752caf508e699d583142e212261f808dacba4f0a88c1cf0bf9d102c891808b5d159067b
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-01-26 20:45:35

Version Info:

Translation: 0x0000 0x04b0
Comments: nandnhptbf
CompanyName: iwanahdnhq
FileDescription: vgljeqrzgp
FileVersion: 2.3.4.4
InternalName: testing.exe
LegalCopyright: zeszcazdtj
OriginalFilename: testing.exe
ProductName: uowodjohwr
ProductVersion: 2.3.4.4
Assembly Version: 2.3.4.4

PWS:MSIL/Stealer.DHB!MTB also known as:

tehtrisGeneric.Malware
MicroWorld-eScanIL:Trojan.MSILZilla.4970
FireEyeGeneric.mg.3521025207ac71c0
SkyhighArtemis!Trojan
McAfeeArtemis!3521025207AC
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Discord.Win32.668
SangforTrojan.MSIL.Discord.BY
K7AntiVirusPassword-Stealer ( 00559f2e1 )
AlibabaTrojanPSW:MSIL/Stealer.bc8459ac
K7GWPassword-Stealer ( 00559f2e1 )
ArcabitIL:Trojan.MSILZilla.D136A
BitDefenderThetaGen:NN.ZemsilF.36792.am0@am5ZV2k
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/PSW.Discord.BY
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-PSW.Multi.Disco.gen
BitDefenderIL:Trojan.MSILZilla.4970
NANO-AntivirusTrojan.Win32.Discord.gxfemg
AvastWin32:Trojan-gen
TencentWin32.Trojan-QQPass.QQRob.Vsmw
EmsisoftIL:Trojan.MSILZilla.4970 (B)
F-SecureTrojan.TR/PSW.Discord.yqnxn
DrWebTrojan.PWS.Discord.24
VIPREIL:Trojan.MSILZilla.4970
SophosMal/Generic-S
IkarusTrojan.MSIL.PSW
JiangminTrojan.PSW.MSIL.qos
AviraTR/PSW.Discord.yqnxn
Antiy-AVLTrojan[PSW]/MSIL.Discord
Kingsoftmalware.kb.c.991
MicrosoftPWS:MSIL/Stealer.DHB!MTB
ZoneAlarmHEUR:Trojan-PSW.Multi.Disco.gen
GDataMSIL.Trojan-Stealer.AnarchyGrabber.C
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.C3532504
ALYacIL:Trojan.MSILZilla.4970
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Discord.BY!tr.pws
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove PWS:MSIL/Stealer.DHB!MTB?

PWS:MSIL/Stealer.DHB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment