Trojan

IL:Trojan.MSILZilla.10950 (file analysis)

Malware Removal

The IL:Trojan.MSILZilla.10950 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.10950 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine IL:Trojan.MSILZilla.10950?


File Info:

name: 58E2ADBD9B9050F89AED.mlw
path: /opt/CAPEv2/storage/binaries/43a207107ebeccad4fd6f103f9d00ff5af6f9ae4f7e74776b05f82a99886efa2
crc32: 1705361A
md5: 58e2adbd9b9050f89aed6ed6c537186a
sha1: f132124986a837d7268dd71f5041049287ced0fa
sha256: 43a207107ebeccad4fd6f103f9d00ff5af6f9ae4f7e74776b05f82a99886efa2
sha512: 37544b2d72f0d3a1fbc5e04d5a88237f668ae194ee155f0163e25663087dbbcfb5c04f09df04d2b2a4520f58f40cec35f35f6c56eda8de5c499c88ff458fc688
ssdeep: 196608:R2MFP8w1emmTZijUtzaHvKPteZDkR5g53HRVu7vHDpS1IqBRU7kCs2q:RXB8wmT8jUOPutOuK53xVu7vHhqBa4Cs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AA61249BDC3D957D570163F7B62C21123A5E84E978AEF0F60E8B3AF99567248ED20C0
sha3_384: 7f659a70fae6d296f13322408d2e4636cc85e0b582f3e81bf24071255439348bb440ea05fcbeb5d472a67745d1538756
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-27 21:30:38

Version Info:

Translation: 0x0000 0x04b0
Comments: Gt Auto Ccs by RealGoblins
CompanyName: Sanad Software
FileDescription: RealGoblins CCS
FileVersion: 3.0.3.0
InternalName: LanX.exe
LegalCopyright: Copyright © 1996-2018 VideoLAN and VLC Author
OriginalFilename: LanX.exe
ProductVersion: 3.0.3.0
Assembly Version: 3.0.3.0

IL:Trojan.MSILZilla.10950 also known as:

LionicTrojan.Win32.Zilla.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.58e2adbd9b9050f8
McAfeeArtemis!58E2ADBD9B90
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 0058b03d1 )
AlibabaTrojanPSW:MSIL/Disstl.467075c4
K7GWPassword-Stealer ( 0058b03d1 )
Cybereasonmalicious.986a83
CyrenW32/Azorult.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Growtopia.NK
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderIL:Trojan.MSILZilla.10950
MicroWorld-eScanIL:Trojan.MSILZilla.10950
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-psw.Growtopia.Szbu
Ad-AwareIL:Trojan.MSILZilla.10950
EmsisoftIL:Trojan.MSILZilla.10950 (B)
TrendMicroTROJ_GEN.R002C0DKR21
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.10950
JiangminTrojan.PSW.MSIL.cxzs
AviraBDS/Backdoor.Gen
GridinsoftRansom.Win32.AzorUlt.sa
MicrosoftTrojan:MSIL/Disstl.AMD!MTB
AhnLab-V3Trojan/Win.Disstl.C4794960
BitDefenderThetaGen:NN.ZemsilF.34062.@p0@aOGYrrm
ALYacIL:Trojan.MSILZilla.10950
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0DKR21
YandexTrojan.PWS.Growtopia!8cSuCyr1ctk
IkarusTrojan.MSIL.PSW
eGambitUnsafe.AI_Score_78%
FortinetMSIL/Growtopia.NK!tr.pws
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILZilla.10950?

IL:Trojan.MSILZilla.10950 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment