Trojan

IL:Trojan.MSILZilla.16286 removal tips

Malware Removal

The IL:Trojan.MSILZilla.16286 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.16286 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine IL:Trojan.MSILZilla.16286?


File Info:

name: E792853A2BA919F4C464.mlw
path: /opt/CAPEv2/storage/binaries/d2afd7d4857381debb3320be9c48bec9a28b4df5427c256e1da49e37d60b4f32
crc32: 9871CC4D
md5: e792853a2ba919f4c46477b509bc8568
sha1: 0ba64d4fe22820d476f7e594e71d095d1e1a3ac2
sha256: d2afd7d4857381debb3320be9c48bec9a28b4df5427c256e1da49e37d60b4f32
sha512: 2940bc33423daad9816feaac6c5a72471149dbf3db0e860823a2d2e677da6562d2c0da800d17b2d1294d943c6dd14ac2664f62a3967d950ffe8b2b1130258585
ssdeep: 6144:fjUPkZK+JW+wBZJW3OHnsPvmY2r/vZrArj9vYljMNW30YGzFufPXK6j/WRrlKRp3:Mqj9wS3YG5uK4dp7rkHkrh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18EA45A51B3138727CC2C38F879123D231BC9F9D1BAEAA971C53DC586714A8E61C7E5A8
sha3_384: 87e220027182d1ec5005fd67e208b64a5266fe72e4d974ce1601d9c0f7a327ced606922db1202c026ea5c205e23d06b4
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-09-05 00:03:48

Version Info:

FileDescription: Ramus ultimate
Translation: 0x0000 0x0000

IL:Trojan.MSILZilla.16286 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Zbot.m6zD
tehtrisGeneric.Malware
DrWebTrojan.PWS.Panda.655
MicroWorld-eScanIL:Trojan.MSILZilla.16286
FireEyeGeneric.mg.e792853a2ba919f4
CAT-QuickHealTrojan.GenericFC.S14889194
McAfeeBackDoor-FCDC!E792853A2BA9
CylanceUnsafe
VIPREIL:Trojan.MSILZilla.16286
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.a2ba91
BitDefenderThetaGen:NN.ZemsilF.34682.Cm1@aaRfLJe
SymantecPacked.Generic.466
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.FBM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.16286
NANO-AntivirusTrojan.Win32.Panda.dnoqff
AvastMSIL:GenMalicious-AAV [Trj]
TencentWin32.Trojan.Generic.Simw
Ad-AwareIL:Trojan.MSILZilla.16286
EmsisoftIL:Trojan.MSILZilla.16286 (B)
ZillyaTrojan.Injector.Win32.264157
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/MSIL-AEZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.baxat
GoogleDetected
AviraTR/Spy.Gen8
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.3303
MicrosoftPWS:Win32/Zbot.gen!CI
GDataIL:Trojan.MSILZilla.16286
CynetMalicious (score: 99)
AhnLab-V3Spyware/Win32.Zbot.R118003
Acronissuspicious
ALYacIL:Trojan.MSILZilla.16286
MalwarebytesTrojan.Agent
IkarusTrojan-Spy.Zbot
FortinetMSIL/Injector.EJD!tr
AVGMSIL:GenMalicious-AAV [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILZilla.16286?

IL:Trojan.MSILZilla.16286 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment