Trojan

IL:Trojan.MSILZilla.13019 removal tips

Malware Removal

The IL:Trojan.MSILZilla.13019 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.13019 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine IL:Trojan.MSILZilla.13019?


File Info:

name: D85A569692DCC30D7138.mlw
path: /opt/CAPEv2/storage/binaries/636eade7adbff93edfb59548f6861fcf4e26ff9bcd2b413a1fb5cac290e1e05b
crc32: 0DF9460C
md5: d85a569692dcc30d7138af19b201f3be
sha1: 9fc5b70cb87c180b9815e808a8041fe44b1faa30
sha256: 636eade7adbff93edfb59548f6861fcf4e26ff9bcd2b413a1fb5cac290e1e05b
sha512: 6a7220604ce0f8c469ae570e59e5e516b249fb02a5a47d95b319e2f4c68e9a26c7afa4c87532c9e76952c6e08b3a1ae72cffd19f0fff12ac99d7ff70de3f99e8
ssdeep: 768:JTJNCSEqCJjQsBkWB2xxcYGFIwiki5zc6X666666BsTShnSTRd/PKZy7sjKrQD:JTSSVCJ8sBp2wYGq5Ad/PKwoKrg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137B31C63314489BBF2131CBA4C1ED2B22597AD64505AA51D71AE371F18F232223EF76F
sha3_384: b4b4b938f1bb836ecec22831d6ac262cb8b8ad92d8320ac0de2531848886ea7a4f72c20a24c717fe0ee2bd1d0cf0bcfb
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-31 23:14:01

Version Info:

Translation: 0x0000 0x04b0
Comments: XPS Viewer
CompanyName: Microsoft Corporation
FileDescription: XPS Viewer
FileVersion: 10.0.19041.1052
InternalName: ConsoleApp3.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: ConsoleApp3.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1052
Assembly Version: 10.0.19041.1052

IL:Trojan.MSILZilla.13019 also known as:

LionicTrojan.Win32.Ursu.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.13019
FireEyeGeneric.mg.d85a569692dcc30d
McAfeeArtemis!D85A569692DC
AlibabaTrojanSpy:MSIL/Quasar.0f6eb931
Cybereasonmalicious.692dcc
SymantecMSIL.Downloader!gen7
ESET-NOD32a variant of MSIL/Kryptik.ADWM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Quasar.gen
BitDefenderIL:Trojan.MSILZilla.13019
AvastWin32:Trojan-gen
TencentMsil.Trojan-spy.Quasar.Wrgk
Ad-AwareIL:Trojan.MSILZilla.13019
EmsisoftIL:Trojan.MSILZilla.13019 (B)
TrendMicroTrojanSpy.Win32.SABSIK.USMANA122
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.13019
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win32.Gen.se!i
ArcabitIL:Trojan.MSILZilla.D32DB
MicrosoftTrojan:Win32/Tnega!MSR
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34114.gm0@aeWC05j
ALYacBackdoor.MSIL.Quasar.gen
MAXmalware (ai score=81)
MalwarebytesTrojan.Downloader.MSIL
TrendMicro-HouseCallTrojanSpy.Win32.SABSIK.USMANA122
RisingMalware.FakePDF/ICON!1.D51A (CLASSIC)
YandexTrojan.Agent!WGEcOyjGjSw
IkarusTrojan-Downloader.MSIL.Agent
eGambitUnsafe.AI_Score_98%
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove IL:Trojan.MSILZilla.13019?

IL:Trojan.MSILZilla.13019 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment