Worm

Worm:Python/Malgent!MSR removal instruction

Malware Removal

The Worm:Python/Malgent!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Python/Malgent!MSR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Python/Malgent!MSR?


File Info:

name: 6D8F66E1D2A8EF71A67F.mlw
path: /opt/CAPEv2/storage/binaries/65791b478996e01159524a4e0a4f5c24dc6608e6b1347dbfd9c396bd93ef5d9d
crc32: 6A41276C
md5: 6d8f66e1d2a8ef71a67f677984b7b453
sha1: 969338429bc9fce8b16ac6fca5b723187af12245
sha256: 65791b478996e01159524a4e0a4f5c24dc6608e6b1347dbfd9c396bd93ef5d9d
sha512: cb8dba7dd38955e45b3bfe69be2145517a3ad6466c9158981c1c066555b8c0da7261a58a1f330bef93fbc3e2de8e60c39059408d3a104789cfdfe5bec3d9ad94
ssdeep: 98304:eJQaLXTZx9lyUZJ0HArfMgHHvpP3VdXVQ//i6rQUKx44bacL7Zc:eJQaLnyUE8EMdXVQhroxXbZ3q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED26CEA1B401F035DDE908B7EB7E89B28D6C8E15371A38E3A5F87489C1760E1B53925F
sha3_384: 30f456f58ddb3bd1690f01d39cc46ffcf39f4c709e98162578e5cd9fa944277edaf8ba2452873e0db9a7d5f4e20e8c7d
ep_bytes: e872030000e936fdffff8bff558bec8b
timestamp: 2008-11-10 09:40:35

Version Info:

0: [No Data]

Worm:Python/Malgent!MSR also known as:

BkavW32.FamVT.TasfaSO.Trojan
DrWebPython.Siggen.13
MicroWorld-eScanTrojan.Agent.FKUK
FireEyeGeneric.mg.6d8f66e1d2a8ef71
ALYacTrojan.Agent.FKUK
ZillyaWorm.Agent.Win32.42197
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004fffe01 )
K7GWTrojan ( 004fffe01 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWorm.Win32.Python.A
CyrenW32/PYFileDel.A.gen!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32Python/Agent.K
APEXMalicious
TrendMicro-HouseCallWorm.Win32.PYSIS.SM
KasperskyHEUR:Worm.Python.Generic
BitDefenderTrojan.Agent.FKUK
NANO-AntivirusTrojan.Py2Exe.PyAgent.eqmocu
AvastWin32:Dropper-gen [Drp]
TencentMalware.Win32.Gencirc.10b3fe34
Ad-AwareTrojan.Agent.FKUK
EmsisoftTrojan.Agent.FKUK (B)
VIPRETrojan.Agent.FKUK
TrendMicroWorm.Win32.PYSIS.SM
McAfee-GW-EditionTrojan-FLOM!6D8F66E1D2A8
Trapminemalicious.moderate.ml.score
SophosML/PE-A + W32/PYFileDel-B
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1MOOI0G
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Worm.Gen
MAXmalware (ai score=85)
MicrosoftWorm:Python/Malgent!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blakamba.C2411905
Acronissuspicious
McAfeeTrojan-FLOM!6D8F66E1D2A8
VBA32Trojan.Wacatac
MalwarebytesWorm.Agent
YandexTrojan.Worm!rH3RF18gmPw
IkarusWorm.Python.Agent
MaxSecureTrojan.Malware.73947986.susgen
FortinetW32/Agent.K!tr
AVGWin32:Dropper-gen [Drp]
Cybereasonmalicious.1d2a8e

How to remove Worm:Python/Malgent!MSR?

Worm:Python/Malgent!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment