Trojan

IL:Trojan.MSILZilla.17662 removal guide

Malware Removal

The IL:Trojan.MSILZilla.17662 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.17662 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine IL:Trojan.MSILZilla.17662?


File Info:

name: E87536C3255FDB055600.mlw
path: /opt/CAPEv2/storage/binaries/aeb1614fbbb4ad0936029da8cf7f24eca77c6a5f25d30348fe4ecf7d7a3e8256
crc32: 5953FBC8
md5: e87536c3255fdb0556009a7847f74037
sha1: 57803e53dcb98c4840dd8d34abfeff45f7381de1
sha256: aeb1614fbbb4ad0936029da8cf7f24eca77c6a5f25d30348fe4ecf7d7a3e8256
sha512: 66e6358b19dd50b7a4b6f7ffb1e80765117270b5c4f7710c2a285c4b3d0ea4990758c9593ccb1aafb6d2cab09f7ca5e2fa140d826ba834556d58d0bf3e176309
ssdeep: 12288:UUO63yNcuUvS54CAcNBOjiQvZezdXixhmaw2kGy7fAoz:UqqtetcNBcpbhdw269z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19ED47C0CB6F6A664E9AD4336C5D3D4644273FD65AA07EB6A3CE537EE0E30398C446807
sha3_384: 6bbdae40a080cca059da167341707fbdc152a38215baadb1023af84081d9e1da0b5519bab9ef800dbd65ed40b230ef4e
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-03-22 17:34:54

Version Info:

Translation: 0x0409 0x04e4
FileDescription: Resource viewer, decompiler & recompiler
FileVersion: 4.5.30.180
InternalName: ResHack
LegalCopyright: (c) Angus Johnson 1999-2016
OriginalFilename: ResHack
ProductVersion: 4.5.0.0
Assembly Version: 0.0.0.0
CompanyName: Angus Johnson

IL:Trojan.MSILZilla.17662 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanIL:Trojan.MSILZilla.17662
FireEyeGeneric.mg.e87536c3255fdb05
ALYacIL:Trojan.MSILZilla.17662
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056f0581 )
K7GWTrojan ( 0056f0581 )
Cybereasonmalicious.3255fd
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Packed.MultiPacked.Z
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Albertina.gen
BitDefenderIL:Trojan.MSILZilla.17662
AvastMSIL:GenMalicious-AZQ [Trj]
TencentMalware.Win32.Gencirc.11f0f897
Ad-AwareIL:Trojan.MSILZilla.17662
SophosML/PE-A
DrWebTrojan.MulDrop20.684
ZillyaTrojan.MultiPacked.Win32.4433
McAfee-GW-EditionRDN/Generic.rp
EmsisoftIL:Trojan.MSILZilla.17662 (B)
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.17662
AviraHEUR/AGEN.1236000
Antiy-AVLTrojan/Generic.ASMalwS.355D4EC
ArcabitIL:Trojan.MSILZilla.D44FE
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.FCN.C5003631
McAfeeRDN/Generic.rp
MAXmalware (ai score=88)
MalwarebytesTrojan.Injector
YandexTrojan.MultiPacked!lieL1TzVwzk
IkarusTrojan.MSIL.MultiPacked
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34606.Km0@aqugYuki
AVGMSIL:GenMalicious-AZQ [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILZilla.17662?

IL:Trojan.MSILZilla.17662 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment