Malware

PWS:Win32/Mocrt!pz removal

Malware Removal

The PWS:Win32/Mocrt!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Mocrt!pz virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Enumerates physical drives
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Mocrt!pz?


File Info:

name: 6326ACF35EB6CCFCFB49.mlw
path: /opt/CAPEv2/storage/binaries/48b7251fd7b206a25cd1aac1215b9cf8027a7c6dd594daffa5c91b17ba98261c
crc32: 6FBB6B06
md5: 6326acf35eb6ccfcfb4990c4db66fd40
sha1: fa8560c065f093fb74c5741552cc70a878b8e3e6
sha256: 48b7251fd7b206a25cd1aac1215b9cf8027a7c6dd594daffa5c91b17ba98261c
sha512: 903cb31fa23474c8343cde17c499b2f99d4f922d9201b4bdba448abd2ad80ce3f27b1c1e357af913763466cefb19aba40e404f21e8dc43ed7602e6987e5683b6
ssdeep: 49152:jk3WKFX9OR6sh80L+4QPlr6TzkhbldrY/xSJxSbTJyjzEV5MAjPqXQV:oJFtOR6sh80L+4QPlr6Tzk31Y/6xSbdQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AC5BF66B74E90B2D1B21031661DE76704A974321F6A50C7F7C4AF2E29F06D2FA39E07
sha3_384: 1173a21f36260445a086a5c0558e5c3562a832f33bb1376fef0f8a4a98986fac4b94834d0ea6eb7f72e53a9002a43bc2
ep_bytes: e87b040000e980feffff558bec5156ff
timestamp: 2018-08-11 07:36:16

Version Info:

0: [No Data]

PWS:Win32/Mocrt!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.34119618
FireEyeGeneric.mg.6326acf35eb6ccfc
CAT-QuickHealDownldr.Adload.S3351678
SkyhighBehavesLike.Win32.Generic.vh
McAfeeSoftcnapp
Cylanceunsafe
VIPRETrojan.Generic.34119618
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005631a71 )
K7GWAdware ( 005631a71 )
Cybereasonmalicious.065f09
BitDefenderThetaGen:NN.ZexaF.36744.NAW@aKfbyFdj
SymantecPUA.Downloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
ClamAVWin.Malware.Softcnapp-6787524-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.34119618
NANO-AntivirusTrojan.Win32.Softcnapp.fhokxf
AvastWin32:MalwareX-gen [Trj]
RisingAdware.Downloader!1.BBEC (CLASSIC)
SophosSoftcnapp (PUA)
F-SecureHeuristic.HEUR/AGEN.1319114
DrWebAdware.Softcnapp.92
ZillyaTrojan.Generic.Win32.1392186
EmsisoftTrojan.Generic.34119618 (B)
IkarusPUA.Softcnapp
GDataWin32.Trojan.PSE.17KA8KO
JiangminTrojan.Generic.cnulk
GoogleDetected
AviraHEUR/AGEN.1319114
VaristW32/S-2a1c663c!Eldorado
Antiy-AVLGrayWare/Win32.Softcnapp.bc
XcitiumApplication.Win32.AdWare.Softcnapp.O@80ok4p
ArcabitTrojan.Generic.D2089FC2
ViRobotAdware.Softcnapp.2741760.AR
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Mocrt!pz
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Helper.R233980
Acronissuspicious
VBA32BScope.Adware.Puwaders
ALYacTrojan.Generic.34119618
MAXmalware (ai score=88)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentTrojan.Win32.Generic.e
YandexTrojan.GenAsa!Nl/kgF1kZRM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Softcnapp
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PWS:Win32/Mocrt!pz?

PWS:Win32/Mocrt!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment