Malware

What is “PWS:Win32/Mocrt!rfn”?

Malware Removal

The PWS:Win32/Mocrt!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Mocrt!rfn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:Win32/Mocrt!rfn?


File Info:

crc32: AF2C1331
md5: a7eaed0e8155a3e0a5eed861fc1985fc
name: A7EAED0E8155A3E0A5EED861FC1985FC.mlw
sha1: 07d7143ccb7b0aa25e90e38487dac448d8fd034d
sha256: 73f7c4bf5b506ae0339055bc25da760e19054b866b0e58b06d8e1646c848ba87
sha512: e6e621acd22adc69a0ef598678fada4960888f45eb67eb7caf86c47a5cc536101d69e4b186c0d6e2d7a1fd4491788995adcb44617a03f9e913a8015e7702beb9
ssdeep: 12288:GIbsBDU0I6+Tu0TJ0N1oYgeOFSA7W2FeDSIGVH/KIDgDgUeHbY1tkw:GIbGD2JTu0GoXQDbGV6eH8tkw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2018
InternalName: unpack200
FileVersion: 8.0.1810.13
Full Version: 1.8.0_181-b13
CompanyName: Oracle Corporation
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.1810.13
FileDescription: Java(TM) Platform SE binary
OriginalFilename: unpack200.exe
Translation: 0x0000 0x04b0

PWS:Win32/Mocrt!rfn also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.ECLV
FireEyeGeneric.mg.a7eaed0e8155a3e0
ALYacGenPack:Trojan.Agent.ECLV
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00543ea81 )
BitDefenderGenPack:Trojan.Agent.ECLV
K7GWTrojan ( 00543ea81 )
Cybereasonmalicious.e8155a
TrendMicroTrojanSpy.Win32.AVEMARIA.SMTH
CyrenW32/Injector.ACJ.gen!Eldorado
SymantecPacked.Generic.526
APEXMalicious
AvastSf:ShellCode-CU [Trj]
ClamAVWin.Malware.Ursu-6793772-0
KasperskyTrojan.Win32.Delf.tibh
NANO-AntivirusTrojan.Win32.Delf.flihmx
TencentMalware.Win32.Gencirc.10b076dd
Ad-AwareGenPack:Trojan.Agent.ECLV
SophosMal/Agent-ATS
F-SecureHeuristic.HEUR/AGEN.1120245
DrWebTrojan.Siggen6.54687
InvinceaML/PE-A + Mal/Agent-ATS
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGenPack:Trojan.Agent.ECLV (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Dico.lu
AviraHEUR/AGEN.1120245
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Fuerboos
MicrosoftPWS:Win32/Mocrt!rfn
GridinsoftTrojan.Win32.Agent.bot!s1
ArcabitGenPack:Trojan.Agent.ECLV
ZoneAlarmTrojan.Win32.Delf.tibh
GDataGenPack:Trojan.Agent.ECLV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Agent.R281398
Acronissuspicious
McAfeeGenericRXAA-AA!A7EAED0E8155
TACHYONTrojan/W32.DP-Delf.1130496
VBA32Trojan.Fuery
MalwarebytesSpyware.LokiBot
PandaTrj/Genetic.gen
ZonerTrojan.Win32.97652
ESET-NOD32a variant of Win32/Injector.ELDH
TrendMicro-HouseCallTrojanSpy.Win32.AVEMARIA.SMTH
RisingTrojan.Injector!1.B53C (CLASSIC)
IkarusTrojan.Win32.Injector
eGambitTrojan.Generic
FortinetW32/Injector.ECZY!tr
BitDefenderThetaAI:Packer.BCE7A70017
AVGSf:ShellCode-CU [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM13.0.3FBB.Malware.Gen

How to remove PWS:Win32/Mocrt!rfn?

PWS:Win32/Mocrt!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment