Malware

Troj/MSIL-NWG removal guide

Malware Removal

The Troj/MSIL-NWG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/MSIL-NWG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Troj/MSIL-NWG?


File Info:

crc32: 326DC7D2
md5: 97721c4b6ba9e4135bd2ec77a61f66b1
name: bnt.exe
sha1: fa982e3fef0127414f456b7e18417943426724aa
sha256: bd894d77abe2630a54e027db21bb5028f9cad2ea28babd18aa0a9b74e34dd8c5
sha512: 18c55f92e56768d0291d672bbbc6b90448992839a143e9191baf95c27fd1ea7a0df5bb1bfc02cc411ca30ef5c6d747251dc816ae2ceeb3f2a0ee2faec4366d53
ssdeep: 6144:bR91W7s66zZfJI1+BWMTDi5pXrlPvbezaFNfLb/oWTV:V91WYlPCeDi/pSenoWTV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: poFKqAZlXNhmuIQHLtZH.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: poFKqAZlXNhmuIQHLtZH.exe

Troj/MSIL-NWG also known as:

DrWebTrojan.PWS.AgenslaNET.1
MicroWorld-eScanGen:Variant.Razy.577898
FireEyeGeneric.mg.97721c4b6ba9e413
Qihoo-360HEUR/QVM03.0.C205.Malware.Gen
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Agensla.i!c
SangforMalware
K7AntiVirusTrojan ( 0056069a1 )
BitDefenderGen:Variant.Razy.577898
K7GWTrojan ( 0056069a1 )
Cybereasonmalicious.fef012
TrendMicroBackdoor.MSIL.REMCOS.THCOBBO
BitDefenderThetaGen:NN.ZemsilF.34098.sm0@aWQHryn
F-ProtW32/MSIL_Troj.RC.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-7426372-0
GDataGen:Variant.Razy.577898
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.a
AlibabaBackdoor:MSIL/Agensla.0d978e4e
NANO-AntivirusTrojan.Win32.Agensla.hdlffv
TencentWin32.Trojan.Spy.Htvm
Ad-AwareGen:Variant.Razy.577898
SophosTroj/MSIL-NWG
ComodoMalware@#1cmypmyaeenur
F-SecureTrojan.TR/Spy.Gen8
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
EmsisoftTrojan-Spy.Agent (A)
SentinelOneDFI – Malicious PE
CyrenW32/MSIL_Troj.RC.gen!Eldorado
AviraTR/Spy.Gen8
MAXmalware (ai score=85)
Antiy-AVLTrojan[PSW]/MSIL.Agensla
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D8D16A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.a
MicrosoftBackdoor:MSIL/Remcos!rfn
AhnLab-V3Trojan/Win32.AgentTesla.C3450450
Acronissuspicious
ALYacGen:Variant.Razy.577898
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.DF
TrendMicro-HouseCallBackdoor.MSIL.REMCOS.THCOBBO
RisingSpyware.AgentTesla!1.B864 (CLOUD)
YandexWorm.Autorun!HsM+GXOrE5Q
IkarusWorm.MSIL.Autorun
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.AES!tr.spy
AVGWin32:FileinfectorX-gen [Trj]
AvastWin32:FileinfectorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Troj/MSIL-NWG?

Troj/MSIL-NWG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment