Malware

What is “PWS:Win32/Msnpass.C”?

Malware Removal

The PWS:Win32/Msnpass.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Msnpass.C virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine PWS:Win32/Msnpass.C?


File Info:

crc32: 24C3B320
md5: ca4b41dd8aa8e6b312a4d145b317987b
name: CA4B41DD8AA8E6B312A4D145B317987B.mlw
sha1: 61546865052ad91be4cb912f7cc71ce54a9ab623
sha256: 926a94d4203d55d24b43c67c4068a20197aec7be5ffa3fceaa7d88ede7a4372b
sha512: e7a5ccea6958c41c061cb420907c9836721e158eb3570c350c45ede48c44c8ac3965b3f25d67cc03768e1014e8d51e94bef7f27dfabaf40b5b0ca722af629444
ssdeep: 3072:LxWUM7FPcYpPaCw5U+pS2gFSarZACeiswxVKKQwjHP7l2:t+7FPciPEPpS1Ff9swnJjv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: project1
FileVersion: 1.00
CompanyName: Particular
ProductName: inicio
ProductVersion: 1.00
OriginalFilename: project1.exe

PWS:Win32/Msnpass.C also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Click.20169
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.ii0arfdGOZpiu
CylanceUnsafe
ZillyaTrojan.Vilsel.Win32.21574
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaWorm:Win32/Vilsel.b4220000
K7GWTrojan ( 00171bc41 )
K7AntiVirusTrojan ( 00171bc41 )
CyrenW32/SuspPack.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.NTU
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Vilsel.agwm
BitDefenderGen:Trojan.Heur.ii0arfdGOZpiu
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SUPERAntiSpywareWorm.Ructo/Variant
MicroWorld-eScanGen:Trojan.Heur.ii0arfdGOZpiu
TencentWin32.Trojan.Vilsel.Syrr
Ad-AwareGen:Trojan.Heur.ii0arfdGOZpiu
SophosML/PE-A + Mal/Particula-A
ComodoTrojWare.Win32.PSW.Ldpinch.~NNT@1op6ij
BitDefenderThetaAI:Packer.85F5184F1D
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroWORM_RUCTO.SMI
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.ca4b41dd8aa8e6b3
EmsisoftGen:Trojan.Heur.ii0arfdGOZpiu (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Vilsel.wtg
Webrootnone
AviraTR/Crypt.CFI.Gen
eGambitGeneric.Malware
MicrosoftPWS:Win32/Msnpass.C
GDataGen:Trojan.Heur.ii0arfdGOZpiu
AhnLab-V3Trojan/Win32.MSNPass.R1900
Acronissuspicious
McAfeeGeneric BackDoor.wg
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_RUCTO.SMI
RisingWorm.VB!8.30 (CLOUD)
YandexTrojan.Vilsel.Gen!Pac.3
IkarusTrojan.Win32.Vilsel
MaxSecureTrojan.Vilsel.agwm
FortinetW32/Vilsel.GA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PWS:Win32/Msnpass.C?

PWS:Win32/Msnpass.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment