Trojan

Trojan:MSIL/Polyransom.psyF!MTB removal guide

Malware Removal

The Trojan:MSIL/Polyransom.psyF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Polyransom.psyF!MTB virus can do?

  • Authenticode signature is invalid

How to determine Trojan:MSIL/Polyransom.psyF!MTB?


File Info:

name: 854D19F289EC38ED20FF.mlw
path: /opt/CAPEv2/storage/binaries/ffb1cf0925183c7c1511bd6532743e35bc51f5c2266d0df6ca355d2bc9349a66
crc32: E8E61D82
md5: 854d19f289ec38ed20ffd484b5a340ae
sha1: 2cf183948890a0f4edd068a61cf2d45c24ef2f6e
sha256: ffb1cf0925183c7c1511bd6532743e35bc51f5c2266d0df6ca355d2bc9349a66
sha512: d60db698c2324c3e9d9430510bb13bb9ec800bb697ac27138aa54ada37a0d35a692cb79a66d8a7b58e86d78ab856f071c1d60811463d85696f02363761ff472a
ssdeep: 768:zfzq4i2QiASwMAaTsNJnIDpJiV3zqsO9mZydalfuV3lVwS9b4G:zLq4ih7sSJeQFzqr9mOaFufVw8cG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12403F91CBAEE415AD4BBEFF86CFC89998DFAE7121405F56B5480070B5D52F80CA4363A
sha3_384: 1543348ed589632586f8920e9143a9d1be9f291d1773b10e7f552db277fbfc7756a5c3f18f456ebe8f1b64422046dd08
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-05-04 18:23:52

Version Info:

Translation: 0x0000 0x04b0
Comments: CmRccService
FileDescription: CmRccService
FileVersion: 2.4.7.1
InternalName: wIig9xJ6AW
LegalCopyright:
OriginalFilename: wIig9xJ6AW
ProductName: CmRccService
ProductVersion: 2.4.7.1
Assembly Version: 2.4.7.1

Trojan:MSIL/Polyransom.psyF!MTB also known as:

LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.23258
ClamAVWin.Packed.Msilzilla-9953300-0
McAfeeGenericRXUK-YY!854D19F289EC
Cylanceunsafe
VIPREIL:Trojan.MSILZilla.23258
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005955001 )
AlibabaTrojan:MSIL/Polyransom.8c7a21eb
K7GWTrojan ( 005955001 )
Cybereasonmalicious.48890a
VirITTrojan.Win32.MSIL_Heur.A
CyrenW32/MSIL_Agent.DHY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.VIF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderIL:Trojan.MSILZilla.23258
AvastWin32:MalwareX-gen [Trj]
TencentTrojan-Ransom.MSIL.PolyRansom.16000547
EmsisoftIL:Trojan.MSILZilla.23258 (B)
F-SecureHeuristic.HEUR/AGEN.1305561
DrWebTrojan.PackedNET.1575
TrendMicroTROJ_GEN.R03BC0DEK23
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.854d19f289ec38ed
SophosMal/DownLdr-FL
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.23258
AviraHEUR/AGEN.1305561
MAXmalware (ai score=84)
ArcabitIL:Trojan.MSILZilla.D5ADA
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Polyransom.psyF!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Mardom.C5109384
Acronissuspicious
VBA32OScope.Trojan.MSIL.Basic.8
ALYacIL:Trojan.MSILZilla.23258
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DEK23
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.VIF!tr
BitDefenderThetaGen:NN.ZemsilF.36196.cm0@a8x@Sdm
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/Polyransom.psyF!MTB?

Trojan:MSIL/Polyransom.psyF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment