Trojan

Trojan:MSIL/DscStealer.RPZ!MTB removal tips

Malware Removal

The Trojan:MSIL/DscStealer.RPZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/DscStealer.RPZ!MTB virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/DscStealer.RPZ!MTB?


File Info:

name: 434F7C38C3F2B33CD671.mlw
path: /opt/CAPEv2/storage/binaries/4d109d736065b3c16693318d0cde8527287117475a13ad6b717ddf2160cedf3e
crc32: 17CA1329
md5: 434f7c38c3f2b33cd6711a450c9d7516
sha1: 2e5552a9e12fef0bd06df2eaed78471b63ace346
sha256: 4d109d736065b3c16693318d0cde8527287117475a13ad6b717ddf2160cedf3e
sha512: 28fdb6ccce816907bfd946da061f64a879a8f6730d1c73e8101ccec262d6f7c9257830c2fae84f08be69195e0e8ad949bd5d42a20009d751e1344f251f82ed96
ssdeep: 192:459iA3AhnkKgJ2H7UEjkYcDaVKrgIZ4KP9a:45F3At8YHguklawgIz
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T143F1C716B3E84931E8FA47B945B207003374B6525C23EF4C2CD855DA6C33A65ABE3771
sha3_384: 6e5c6876acfbe9e275069af7820723747a76817fad66c284a35ffac503f2ce909329a55959d244d4f57fc0423bb030fd
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-02-09 22:40:25

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: supersex_8317ba46fa48eff4fee969426862a78a3b2abee02ce12c91932dff6a3547a378.exe
LegalCopyright:
OriginalFilename: supersex_8317ba46fa48eff4fee969426862a78a3b2abee02ce12c91932dff6a3547a378.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/DscStealer.RPZ!MTB also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Disco.i!c
MicroWorld-eScanIL:Trojan.MSILZilla.25316
FireEyeGeneric.mg.434f7c38c3f2b33c
ALYacIL:Trojan.MSILZilla.25316
MalwarebytesSpyware.DiscordStealer.MSIL
ZillyaTrojan.Disco.Win32.9207
SangforSpyware.Msil.Agent.V4y2
CrowdStrikewin/malicious_confidence_100% (W)
K7GWSpyware ( 0059ef501 )
K7AntiVirusSpyware ( 0059ef501 )
VirITTrojan.Win32.SpyLoad.LM
CyrenW32/MSIL_Kryptik.IYK.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.EIV
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-PSW.Win32.Disco.gen
BitDefenderIL:Trojan.MSILZilla.25316
NANO-AntivirusTrojan.Win32.Disco.juvqfi
AvastWin32:SpywareX-gen [Trj]
TencentTrojan-Psw.Win32.Disco.kb
TACHYONTrojan-PWS/W32.DN-Disco.8192.B
EmsisoftIL:Trojan.MSILZilla.25316 (B)
DrWebBackDoor.SpyBotNET.56
VIPREIL:Trojan.MSILZilla.25316
TrendMicroTROJ_GEN.R023C0PBI23
McAfee-GW-EditionBehavesLike.Win32.Generic.xt
SophosTroj/Disteal-AB
GDataIL:Trojan.MSILZilla.25316
AviraTR/Spy.Agent.hmkkj
Antiy-AVLTrojan/Win32.Wacatac
ArcabitIL:Trojan.MSILZilla.D62E4
ViRobotTrojan.Win.Z.Disco.8192.BT
ZoneAlarmHEUR:Trojan-PSW.Win32.Disco.gen
MicrosoftTrojan:MSIL/DscStealer.RPZ!MTB
GoogleDetected
AhnLab-V3Trojan/Win.MSILZilla.R559134
McAfeeGenericRXVK-PI!434F7C38C3F2
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R023C0PBI23
RisingSpyware.Agent!8.C6 (CLOUD)
IkarusTrojan.MSIL.Spy
FortinetMSIL/SxDisco.A!tr
AVGWin32:SpywareX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Trojan:MSIL/DscStealer.RPZ!MTB?

Trojan:MSIL/DscStealer.RPZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment