Malware

What is “PWS:Win32/PrimaryPass.AD!MTB”?

Malware Removal

The PWS:Win32/PrimaryPass.AD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/PrimaryPass.AD!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
magicview.ga

How to determine PWS:Win32/PrimaryPass.AD!MTB?


File Info:

crc32: 3BF5991F
md5: cc08084a09b75ba5036ae23bffe9771c
name: CC08084A09B75BA5036AE23BFFE9771C.mlw
sha1: 470e94e14c86839c65fa5a9663e3903a01402b40
sha256: c56da54485cc45f6d2dee79439ec4eacfffba0cbcd494cf6b1eca9277142a1ca
sha512: eaaa9abe0a92d5e6c7e0982c1333b4bd5879cf8759774900247d9d520a6ce0e9e95aa62f1edddfd5440814c26c129b05a53c9eeb1bb3978f7100776f2d6d0193
ssdeep: 1536:DOmv//ZOsSdi2cY2AcMxoL2mfxGDw5OMkVQ0YTGEqn/pg+Izmd:BXZOTdPcMxoGeFOQ0YTGXn/pNUG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/PrimaryPass.AD!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.10958B49
FireEyeGeneric.mg.cc08084a09b75ba5
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360HEUR/QVM20.1.44A7.Malware.Gen
ALYacDeepScan:Generic.MSIL.PasswordStealerA.10958B49
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.10958B49
TrendMicroTSPY_LOKI.SMA
CyrenW32/S-f2ff7de9!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:LokiBot-A [Trj]
ClamAVWin.Trojan.naKocTb-6331389-1
NANO-AntivirusTrojan.Win32.Renos.flotpm
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerA.10958B49
TACHYONTrojan/W32.naKocTb.106496
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PWS.Siggen2.59088
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftTrojan-PSW.Fareit (A)
IkarusTrojan-Spy.Primarypass
AviraTR/Crypt.XPACK.Gen
MicrosoftPWS:Win32/PrimaryPass.AD!MTB
GridinsoftMalware.Win32.Pack.39734!se
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.10958B49
GDataDeepScan:Generic.MSIL.PasswordStealerA.10958B49
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.naKocTb.R270234
Acronissuspicious
McAfeeLokiBot!CC08084A09B7
MAXmalware (ai score=82)
VBA32BScope.Trojan.Agentb
MalwarebytesSpyware.LokiBot
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/PSW.Fareit.L
TrendMicro-HouseCallTSPY_LOKI.SMA
RisingStealer.Agent!1.CA9B (CLASSIC)
YandexTrojan.GenAsa!SBszS2bfSB0
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/GenKryptik.DYST!tr
BitDefenderThetaAI:Packer.59A658E51E
AVGWin32:LokiBot-A [Trj]
Cybereasonmalicious.a09b75
MaxSecureTrojan.Malware.300983.susgen

How to remove PWS:Win32/PrimaryPass.AD!MTB?

PWS:Win32/PrimaryPass.AD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment