Trojan

TrojanPSW.MSIL.Coins removal

Malware Removal

The TrojanPSW.MSIL.Coins is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPSW.MSIL.Coins virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanPSW.MSIL.Coins?


File Info:

crc32: 74F08FED
md5: ce30b015aa522d87ed03920e03c4cb0c
name: CE30B015AA522D87ED03920E03C4CB0C.mlw
sha1: f25a30a9dbaec390c2367d9d8e53c9678fff4bf5
sha256: 34836c1354e015fda4b8f61572ef73c5918d07c82ad75fb77b4911f673c1a1ad
sha512: 857d6693d76de62b65be876d803baa198601fd4d235715fb34171b40129e92b572a12548d2d5b6769795ecfc03e5dadf50b7ac8e1b94c42926f5185eb44cbbfa
ssdeep: 24576:CBFYrgb7Rm0VhhUF54clNf7l4clNfYuRGKxJ:Cwre7Rm0Xo54clH4clRRvxJ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Inc.Infrastructure xa9 2020 Control plugin Inc.Infrastructur
Assembly Version: 2.0.0.0
InternalName: Echelon.exe
FileVersion: 2.0.0.0
CompanyName: Inc.Infrastructure
LegalTrademarks: Inc.Infrastructure
Comments: Control plugin Inc.Infrastructur
ProductName: Inc.Infrastructure
ProductVersion: 2.0.0.0
FileDescription: Inc.Infrastructur Host Driver
OriginalFilename: Echelon.exe

TrojanPSW.MSIL.Coins also known as:

K7AntiVirusPassword-Stealer ( 005282e41 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.29333
ClamAVWin.Packed.GrandSteal-9783630-1
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeArtemis!CE30B015AA52
CrowdStrikewin/malicious_confidence_100% (D)
K7GWPassword-Stealer ( 005282e41 )
Cybereasonmalicious.5aa522
CyrenW32/CoinMiner.FA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.BYF
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Coins.gen
BitDefenderGen:Variant.MSILPerseus.214709
MicroWorld-eScanGen:Variant.MSILPerseus.214709
Ad-AwareGen:Variant.MSILPerseus.214709
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34266.an1@aK5ZIPi
McAfee-GW-EditionBehavesLike.Win32.Fareit.th
FireEyeGeneric.mg.ce30b015aa522d87
EmsisoftGen:Variant.MSILPerseus.214709 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Agent.ssbbt
MicrosoftPWS:MSIL/Echelon.GG!MTB
GDataMSIL.Trojan-Stealer.Agent.AXU
AhnLab-V3Malware/Win.Echelon.C4748544
VBA32TrojanPSW.MSIL.Coins
MAXmalware (ai score=83)
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
RisingStealer.Echelon!1.C655 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen

How to remove TrojanPSW.MSIL.Coins?

TrojanPSW.MSIL.Coins removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment