Trojan

How to remove “IL:Trojan.MSILZilla.18166”?

Malware Removal

The IL:Trojan.MSILZilla.18166 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.18166 virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine IL:Trojan.MSILZilla.18166?


File Info:

name: BCA044D7920800D6C18A.mlw
path: /opt/CAPEv2/storage/binaries/a0156a5aa9daae9d2c856760b948b5097256676a7d919c4f16375aff228fbddb
crc32: 0E4A680B
md5: bca044d7920800d6c18a6ff0c6a79f61
sha1: d4f728213bf82c3f6b82d4dbb999e2f9fe2a2f63
sha256: a0156a5aa9daae9d2c856760b948b5097256676a7d919c4f16375aff228fbddb
sha512: 7d2861948df0954a9ec3b3e3e8d1c4ebd267116fd128fa93b5c07f3f58b0cf2b31d421d2a044efd6b99ce75e458a51415418ad15d3c0303c2e039dcc3c9e122a
ssdeep: 768:Th1IEpKq+8E3jTwEQydUbAc5tuYsxYho:nIEYz3jMmKaYsxmo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194E2C53076941327D12F4CBAC56DB64D4B76A9136409DB9DF8CD33BA4BE2B802642AC3
sha3_384: ddd4dcee5afdf037dd7809e655c3056ae43c97f8d0edf7b02da6226c420c453122275725cb4090662640420592b09c9c
ep_bytes: ff250020400000000000000000000000
timestamp: 2039-05-06 16:27:46

Version Info:

Translation: 0x0000 0x04b0
Comments: update
CompanyName:
FileDescription: update
FileVersion: 1.819.22.3
InternalName: update.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: update.exe
ProductName:
ProductVersion: 1.819.22.3
Assembly Version: 1.819.22.3

IL:Trojan.MSILZilla.18166 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (moderate confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.18166
FireEyeGeneric.mg.bca044d7920800d6
ALYacIL:Trojan.MSILZilla.18166
MalwarebytesTrojan.Crypt.MSIL.Generic
SangforBackdoor.MSIL.Small.gen
K7AntiVirusSpyware ( 00591d531 )
AlibabaBackdoor:MSIL/Generic.e4c02765
K7GWSpyware ( 00591d531 )
Cybereasonmalicious.13bf82
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DQK
TrendMicro-HouseCallTROJ_GEN.R002H0CDL22
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Small.gen
BitDefenderIL:Trojan.MSILZilla.18166
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Backdoor.Small.Pitk
Ad-AwareIL:Trojan.MSILZilla.18166
EmsisoftIL:Trojan.MSILZilla.18166 (B)
F-SecureTrojan.TR/Spy.Agent.pxvxr
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.nm
SophosMal/Generic-S
AviraTR/Spy.Agent.pxvxr
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataIL:Trojan.MSILZilla.18166
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4773609
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=86)
APEXMalicious
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.DQK!tr.spy
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove IL:Trojan.MSILZilla.18166?

IL:Trojan.MSILZilla.18166 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment