Trojan

What is “‘Trojan-PSW.MSIL.Disco'”?

Malware Removal

The ‘Trojan-PSW.MSIL.Disco’ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ‘Trojan-PSW.MSIL.Disco’ virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • CAPE detected the BlackNET malware family

How to determine ‘Trojan-PSW.MSIL.Disco’?


File Info:

name: 511A121333F3CA84197B.mlw
path: /opt/CAPEv2/storage/binaries/889e7f3c146e41dd6b10abae35e45370a43f6a1ab2d8239167c39fe3ad538211
crc32: B57F9A49
md5: 511a121333f3ca84197b4709d1d8f2b3
sha1: bb92ca74ac3abad7875408648b98a1ecdcfcbd90
sha256: 889e7f3c146e41dd6b10abae35e45370a43f6a1ab2d8239167c39fe3ad538211
sha512: 70eae7dae037d67f0318e60c2e27b7b2a95160b7347cb1d62ef423f7c27f543376d1595c3a1eaaf2a8eae0f5cd785023fbf6eeb6337f8af391af551d28766d87
ssdeep: 3072:WKeJurZLusi5w/oV9lRKyfKW63beFEKy+Ffax:7ckdWRPfKWybiA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119C3160277EC5D65E5BECBB4AB725280C7B5FC264922D76C0CC120AD5AF7742A901BE3
sha3_384: f3a003608e9e37a60d946efd0dba2156e96526322deec3791a245b5bf93081f4396830f2eb3b63bde98f4192873473b2
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-12-10 17:51:43

Version Info:

Translation: 0x0000 0x04b0
Comments: Host Process for Windows Services
CompanyName: Microsoft Corporation
FileDescription: Windows Update Assistant
FileVersion: 10.0.18362.1
InternalName: svchost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: svchost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.18362.1
Assembly Version: 10.0.18362.1

‘Trojan-PSW.MSIL.Disco’ also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacIL:Trojan.MSILZilla.6980
MalwarebytesBackdoor.Bladabindi
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052d5341 )
K7GWTrojan ( 005647091 )
Cybereasonmalicious.333f3c
CyrenW32/MSIL_Bladabindi.FN.gen!Eldorado
ESET-NOD32a variant of MSIL/Agent.VC
APEXMalicious
ClamAVWin.Trojan.Razy-9778111-0
Kaspersky‘HEUR:Trojan-PSW.MSIL.Disco.gen’
BitDefenderIL:Trojan.MSILZilla.6980
MicroWorld-eScanIL:Trojan.MSILZilla.6980
AvastWin32:Malware-gen
Ad-AwareIL:Trojan.MSILZilla.6980
EmsisoftIL:Trojan.MSILZilla.6980 (B)
F-SecureTrojan.TR/Crypt.FKM.nncrr
DrWebTrojan.DownLoader34.7684
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.MSIL.BLACKNET.SMDA
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.511a121333f3ca84
SophosML/PE-A + ATK/Blacknet-A
IkarusTrojan.Msil
GDataIL:Trojan.MSILZilla.6980
JiangminTrojan.Generic.gnsfr
AviraTR/Crypt.FKM.nncrr
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.31DE250
ArcabitIL:Trojan.MSILZilla.D1B44
MicrosoftBackdoor:MSIL/Blacknet.GG!MTB
AhnLab-V3Trojan/Win32.Wacatac.C4199561
Acronissuspicious
McAfeeBackDoor-FEBU!511A121333F3
VBA32Malware-Cryptor.MSIL.AgentTesla.Heur
CylanceUnsafe
TrendMicro-HouseCallBackdoor.MSIL.BLACKNET.SMDA
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
YandexTrojan.Agent!kbMiy5NZV6I
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.VC!tr
BitDefenderThetaGen:NN.ZemsilF.34114.hm0@aCOaEn
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.7164915.susgen

How to remove ‘Trojan-PSW.MSIL.Disco’?

'Trojan-PSW.MSIL.Disco' removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment