Trojan

How to remove “Trojan-PSW.MSIL.Reline.ac”?

Malware Removal

The Trojan-PSW.MSIL.Reline.ac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Reline.ac virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Trojan-PSW.MSIL.Reline.ac?


File Info:

crc32: 9FDD1456
md5: f8a7cbf299ea2c26131d1bd3b6d5bd06
name: 1584248056.exe
sha1: 913fb7131947d4afba2c054b66934222e752d39e
sha256: a78df3ea7c9bcf96c6c9db033be7a66d9c418c1acfa3c8efc3c4ba313c5b4fad
sha512: 0fe358304b743bd85674e2c6a3dbfb4da6911b6310a0daadc2e173a5f1b4eb570f88a297db850d3a2c075a6a90266bf1e92e3931daca292fe5862d5b3abe0978
ssdeep: 49152:Tfc57UFfhEBxKpqtUYy/QK+F71yYRbRSmXcoGQf0:TfiUFfhEBMpq+HYqYRbRS0gQc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009-2020 SAMP Systems Incorporated. All rights reserved.
InternalName: Bootstrapper
CompanyName: SAMP Systems Incorporated
ProductName: Bootstrapper Application
FileDescription: Bootstrapper Application
OriginalFilename: SAMP.exe
Translation: 0x0409 0x04b0

Trojan-PSW.MSIL.Reline.ac also known as:

BkavW32.HfsAutoB.
DrWebTrojan.PWS.Siggen2.47835
MicroWorld-eScanTrojan.GenericKD.33707661
FireEyeGeneric.mg.f8a7cbf299ea2c26
Qihoo-360Generic/HEUR/QVM19.1.BBCD.Malware.Gen
ALYacTrojan.GenericKD.33707661
AegisLabTrojan.MSIL.Reline.i!c
SangforMalware
BitDefenderTrojan.GenericKD.33707661
K7GWTrojan ( 005651071 )
Cybereasonmalicious.31947d
BitDefenderThetaGen:NN.ZexaF.34106.@F3@a8otVmoi
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
GDataTrojan.GenericKD.33707661
KasperskyTrojan-PSW.MSIL.Reline.ac
AlibabaTrojanPSW:MSIL/Reline.cb228793
Ad-AwareTrojan.GenericKD.33707661
SophosMal/Generic-S
F-SecureTrojan.TR/PSW.Agent.njjvn
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.rm
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33707661 (B)
IkarusTrojan.MSIL.Spy
WebrootW32.Trojan.Gen
AviraTR/PSW.Agent.njjvn
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D202568D
ZoneAlarmTrojan-PSW.MSIL.Reline.ac
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!F8A7CBF299EA
MAXmalware (ai score=87)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Themida.HKW
TrendMicro-HouseCallTROJ_GEN.R002H09DN20
RisingStealer.Baldr!1.B723 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.91500139.susgen

How to remove Trojan-PSW.MSIL.Reline.ac?

Trojan-PSW.MSIL.Reline.ac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment