Trojan

What is “Trojan-PSW.MSIL.Reline.ewr”?

Malware Removal

The Trojan-PSW.MSIL.Reline.ewr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Reline.ewr virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine Trojan-PSW.MSIL.Reline.ewr?


File Info:

crc32: 39AE7F5E
md5: 8e593c0316afe7dbf9fc0771d3f6618c
name: 8E593C0316AFE7DBF9FC0771D3F6618C.mlw
sha1: a678a6c3bf1a9f92681c2bd112f82e87935d4ed9
sha256: c189ccfd8d06b7bf459bba39fb8fdbc82fbff4f6f9f4d6f7fb0d13e3a062d55d
sha512: 5819d3aa15ba9553c94c39fbecdd13533173e2768cf161f570aa979a6c4011f9c22e4fce921811961ec071c1a7da2c009646f519b75c82da82d811c3a1d9300e
ssdeep: 49152:n5+hFSObPn6gOcnRdgUpbJ23hyhiSFLExRH4NwVlxiz8lVHTIioOFZQ+A:n5aFhjUEvZsohi6L/wVlxiqZ7A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: ImagingDevices.cpl
FileVersion: 6.1.7600.16385
CompanyName: Microsoft Corporation
Builder: Administrator 04:39:53 02/08/2021
Created: 7z SFX Constructor v4.5.0.0 (http://usbtor.ru/viewtopic.php?t=798)
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Imaging Devices Control Panel
OriginalFilename: ImagingDevices.cpl
Translation: 0x0000 0x04b0

Trojan-PSW.MSIL.Reline.ewr also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.Reline.i!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Bulz-9866401-0
ALYacTrojan.GenericKDZ.76746
CylanceUnsafe
SangforInfostealer.MSIL.Reline.gen
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 0057d78e1 )
K7AntiVirusTrojan ( 0057d78e1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/TrojanDropper.Agent.NFZ
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.MSIL.Reline.ewr
BitDefenderTrojan.GenericKDZ.76746
NANO-AntivirusTrojan.Win32.Reline.ixwtic
MicroWorld-eScanTrojan.GenericKDZ.76746
TencentMsil.Trojan-qqpass.Qqrob.Ecuj
SophosMal/Generic-S
DrWebTrojan.Starter.8002
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03FC0DHI21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.8e593c0316afe7db
EmsisoftTrojan-Spy.Agent (A)
JiangminTrojan/CoinMiner.ab.a
AviraTR/Drop.Agent.imfpe
MicrosoftTrojan:Win32/Reline.AMH!MTB
GDataTrojan.GenericKDZ.76746
AhnLab-V3Malware/Win.Generic.C4577661
McAfeeArtemis!8E593C0316AF
MAXmalware (ai score=85)
VBA32Trojan.Hesv
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R03FC0DHI21
IkarusTrojan-Dropper.BAT.Agent
FortinetBAT/Agent.NFZ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan-PSW.MSIL.Reline.ewr?

Trojan-PSW.MSIL.Reline.ewr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment