Trojan

Trojan-PSW.MSIL.Reline.klu information

Malware Removal

The Trojan-PSW.MSIL.Reline.klu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.MSIL.Reline.klu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-PSW.MSIL.Reline.klu?


File Info:

name: A10158B98B91004355DF.mlw
path: /opt/CAPEv2/storage/binaries/7ec43d4bb56c72e29829c58fc18fd2b824f3d0629c4b1752a65be75cb4bc2094
crc32: FB3A4556
md5: a10158b98b91004355df419a4294300c
sha1: 3bc25240d92cfe8d373ef6f8462c3dcbb8c63bdf
sha256: 7ec43d4bb56c72e29829c58fc18fd2b824f3d0629c4b1752a65be75cb4bc2094
sha512: 1357eadf7e1550cb53e830ec06d4ff46d5de98d9bb2a0fb5016aec6ff2ecb11252a152e07f03a52f6a2d3f0dce5a8802f40c78a859ded1a28dd3cd5165a1d6c6
ssdeep: 12288:bD7qoJmghrumv+buBJjRI+UnztjuoQCc+o0jVgIeJ/eB/+c+0L:/IMrfenZjlJcpmgIw2JF+0L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6E42333E1509C8BE50B96B3F402E7259DB1FC26D9A627D32689341F3C743A05D8B96E
sha3_384: 335d5229e510c074895eb2032f428bc35bbc1231910fe4b5022c8ac6151607c4258ad3b86cca702824a3336c46d13aeb
ep_bytes: 6801209f00e801000000c3c3697da788
timestamp: 2021-12-05 14:06:44

Version Info:

0: [No Data]

Trojan-PSW.MSIL.Reline.klu also known as:

MicroWorld-eScanGen:Variant.Fragtor.47946
FireEyeGeneric.mg.a10158b98b910043
CylanceUnsafe
K7AntiVirusTrojan ( 0058b86b1 )
BitDefenderGen:Variant.Fragtor.47946
K7GWTrojan ( 0058b86b1 )
Cybereasonmalicious.0d92cf
BitDefenderThetaGen:NN.ZexaF.34084.RGWaaa5He!mi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.KL
KasperskyTrojan-PSW.MSIL.Reline.klu
Ad-AwareGen:Variant.Fragtor.47946
SophosMal/Generic-S
DrWebTrojan.PWS.Stealer.29333
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftGen:Variant.Fragtor.47946 (B)
IkarusTrojan.Win32.ASProtect
APEXMalicious
GDataGen:Variant.Fragtor.47946
CynetMalicious (score: 100)
VBA32BScope.TrojanPSW.Racealer
ALYacGen:Variant.Fragtor.47946
MAXmalware (ai score=89)
PandaTrj/Genetic.gen
YandexTrojan.PWS.Reline!TVsNgTPErd8
SentinelOneStatic AI – Suspicious PE
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-PSW.MSIL.Reline.klu?

Trojan-PSW.MSIL.Reline.klu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment