Malware

Troj/MSIL-CWS (file analysis)

Malware Removal

The Troj/MSIL-CWS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/MSIL-CWS virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Troj/MSIL-CWS?


File Info:

name: FF5171DB55DCC12DF340.mlw
path: /opt/CAPEv2/storage/binaries/1fb6f68e064d6ec21e5b19a6ceaf17f33a0d5041ef94d825417c04d36413d27d
crc32: EFB6FF10
md5: ff5171db55dcc12df340471be10bd267
sha1: f9b701a7e9aaa2af867929366c1bc20cc16f1969
sha256: 1fb6f68e064d6ec21e5b19a6ceaf17f33a0d5041ef94d825417c04d36413d27d
sha512: ba8ae642b7dd11cd923beaf70f466fbebacf3210de2ccf99c4a9834e76237f3162842773da2be218178cd12f94c3ca7693dad60f365ec0d77931be78b3261def
ssdeep: 96:wuz4E254C2s4y2emZNYrhkmuNMWSoUp9TcE2NYlnlYJnLrL0KffvzBEG6v19RXmY:wui+mrVWSPGVQnlYJLrLTjinDN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F0E1C81667F14275CA5B0B772CB302411B73EA05CE67EB6F088CA3E5C9E31654A62F72
sha3_384: 676c04284101003aa5e1533da9c255522dea5e87f5f0a290e85e885fbf3ffb9b947adb8cf2cbb79a9283e740568db2ec
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-02-23 04:08:09

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Mozilla.exe
LegalCopyright:
OriginalFilename: Mozilla.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Troj/MSIL-CWS also known as:

BkavW32.FamVT.CerbuPKG.Trojan
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DACI
ClamAVWin.Malware.Barys-6804071-0
FireEyeGeneric.mg.ff5171db55dcc12d
CAT-QuickHealTrojan.Mogoogwi.A3
ALYacTrojan.Agent.DACI
Cylanceunsafe
ZillyaTrojan.Agent.Win32.525695
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004be57a1 )
K7GWTrojan ( 004be57a1 )
Cybereasonmalicious.b55dcc
VirITTrojan.Win32.Generic.BAMF
CyrenW32/S-f2a4b9c7!Eldorado
SymantecTrojan Horse
ESET-NOD32MSIL/Agent.QIF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DACI
NANO-AntivirusTrojan.Win32.Agent.dzsvxi
ViRobotTrojan.Win32.Agent.7168.FI
AvastMSIL:Agent-CWF [Trj]
TencentTrojan.MSIL.Agent.hk
TACHYONTrojan/W32.DN-Agent.7168.AL
SophosTroj/MSIL-CWS
F-SecureTrojan.TR/Mogoogwi.qifa
DrWebTrojan.Siggen7.31585
VIPRETrojan.Agent.DACI
TrendMicroWORM_MOGOOGWI.SMHA
McAfee-GW-EditionBehavesLike.Win32.Trojan.zt
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.DACI (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.DACI
JiangminTrojan.Generic01.a
AviraTR/Mogoogwi.qifa
Antiy-AVLTrojan/Win32.Agent
XcitiumTrojWare.MSIL.Agent.QIF@6kzu82
ArcabitTrojan.Agent.DACI
SUPERAntiSpywareBackdoor.Bot/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/Mogoogwi.A
GoogleDetected
AhnLab-V3Trojan/Win32.Zusy.R154407
McAfeeTrojan-FMGK!FF5171DB55DC
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallWORM_MOGOOGWI.SMHA
RisingTrojan.Mogoogwi!1.A1A3 (CLASSIC)
IkarusTrojan.MSIL.Mogoogwi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.QIF!tr
BitDefenderThetaGen:NN.ZemsilF.36250.am0@aeFPVFk
AVGMSIL:Agent-CWF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/MSIL-CWS?

Troj/MSIL-CWS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment