Crack

HackTool:MSIL/Boilod.C!bit (file analysis)

Malware Removal

The HackTool:MSIL/Boilod.C!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:MSIL/Boilod.C!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine HackTool:MSIL/Boilod.C!bit?


File Info:

crc32: 63CF7F50
md5: 75363c46c34315176a3037ae4cf38269
name: svchost.exe
sha1: 7887760491424f8ca1bdb120877424e694b49c8a
sha256: 4af607b8f0a25a2125d39656c45466ce256e10d053c7e4b1b230ea839648b076
sha512: f7fca634abe83973b4e66a20c4e753cd8f69cd287dab84accf06519f3d145b23da421015e7ae70bb37603c9399dcebfaacff2b61154190d39fbb9b3d8ae47eec
ssdeep: 6144:NDHGuuAcmOR2BtZuapu8MycRHmCRPOjavHY23mVcA/E1f2EgxRI:NquuA+R2BtZj9M5RHmCR2jIxgWf2Egx
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: svchost.exe
FileVersion: 1.0.0.0
Comments:
ProductVersion: 1.0.0.0
FileDescription: svchost.exe
OriginalFilename: svchost.exe

HackTool:MSIL/Boilod.C!bit also known as:

DrWebTrojan.DownLoader19.14585
MicroWorld-eScanGen:Heur.MSIL.Androm.3
FireEyeGeneric.mg.75363c46c3431517
ALYacGen:Heur.MSIL.Androm.3
MalwarebytesSpyware.Imminent
ZillyaBackdoor.Androm.Win32.50598
AegisLabTrojan.Win32.Androm.m!c
SangforMalware
K7AntiVirusTrojan ( 005496a61 )
BitDefenderGen:Heur.MSIL.Androm.3
K7GWTrojan ( 005496a61 )
Cybereasonmalicious.6c3431
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.33550.um0@au6GVFn
CyrenW32/Agent.AWH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
GDataGen:Heur.MSIL.Androm.3
KasperskyBackdoor.Win32.Androm.pmfq
NANO-AntivirusTrojan.Win32.Kryptik.ezgaig
RisingBackdoor.Generic!8.CE (TFE:C:FCMHcTgkfZT)
Ad-AwareGen:Heur.MSIL.Androm.3
SophosMal/Generic-S
ComodoTrojWare.MSIL.Boilod.LOL@7iqh32
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BOILOD.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.MSIL.Androm.3 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Agent.AWH.gen!Eldorado
JiangminBackdoor.Androm.ydf
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Androm
Endgamemalicious (high confidence)
ArcabitTrojan.MSIL.Androm.3
ZoneAlarmBackdoor.Win32.Androm.pmfq
MicrosoftHackTool:MSIL/Boilod.C!bit
AhnLab-V3Trojan/Win32.RL_Boilod.C3531475
Acronissuspicious
McAfeePacked-VQ!75363C46C343
MAXmalware (ai score=100)
VBA32CIL.StupidStealth.Heur
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.LOL
TrendMicro-HouseCallTROJ_BOILOD.SM
YandexBackdoor.Androm!Rs6XWf5jsbY
IkarusTrojan.ImminentRAT
FortinetMSIL/Kryptik.LOL!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.69b

How to remove HackTool:MSIL/Boilod.C!bit?

HackTool:MSIL/Boilod.C!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment