Trojan

What is “IL:Trojan.MSILZilla.19239 (B)”?

Malware Removal

The IL:Trojan.MSILZilla.19239 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.19239 (B) virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine IL:Trojan.MSILZilla.19239 (B)?


File Info:

name: 81A8F1E9B06A409AB202.mlw
path: /opt/CAPEv2/storage/binaries/9652dc2a1e17ea2df2455963f66a43973196e6ee98cc4723e98df04a7518c9be
crc32: 740C7766
md5: 81a8f1e9b06a409ab20292ac682a58c6
sha1: 0b6cdd8490b4fc142e6e8d9806b06fe5380bd48a
sha256: 9652dc2a1e17ea2df2455963f66a43973196e6ee98cc4723e98df04a7518c9be
sha512: 78534025a162b01d5e7aa4f4904649a8bdaedb8ae8cdfeefe33ebd4df7ad46708aaeae99003c03c338cac1791e43eabd60b9212ed99f57875cf8e53eff173f42
ssdeep: 1536:6bDPM5dqH3fLB964slUiEM2RLT657xBSN:kPl9K+i2RK57g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17543E146C3F4C22BEDAD0B759476A38386FED316EF12EA1E08C854E25A676C506425F2
sha3_384: f7dd01d3ca86ae2a8c0485a3d3da2ea5b3bb1b655ff783e1da037d98e870a75d6607f142e5bcb52fc5d7af72ffc30a4b
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-07-29 20:03:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: test.exe
LegalCopyright:
OriginalFilename: test.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

IL:Trojan.MSILZilla.19239 (B) also known as:

BkavW32.Common.C81DCD1E
LionicTrojan.Win32.KeyLogger.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDropNET.65
MicroWorld-eScanIL:Trojan.MSILZilla.19239
FireEyeGeneric.mg.81a8f1e9b06a409a
CAT-QuickHealWormrat.A
ALYacIL:Trojan.MSILZilla.19239
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00596b4f1 )
AlibabaTrojanSpy:MSIL/XWormRAT.307e5c8a
K7GWTrojan ( 00596b4f1 )
Cybereasonmalicious.490b4f
BitDefenderThetaGen:NN.ZemsilF.36348.dm0@aKfVOnc
CyrenW32/MSIL_Agent.BUD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FOV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.KeyLogger.gen
BitDefenderIL:Trojan.MSILZilla.19239
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.13eb3b7a
EmsisoftIL:Trojan.MSILZilla.19239 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREIL:Trojan.MSILZilla.19239
TrendMicroTROJ_GEN.R002C0DGT23
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.MSIL.Agent
GDataIL:Trojan.MSILZilla.19239
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Spy]/MSIL.KeyLogger
ArcabitIL:Trojan.MSILZilla.D4B27
ViRobotTrojan.Win.Z.Agent.57344.CAF
ZoneAlarmHEUR:Trojan-Spy.MSIL.KeyLogger.gen
MicrosoftTrojan:MSIL/XWormRAT.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5108156
Acronissuspicious
McAfeeArtemis!81A8F1E9B06A
MalwarebytesTrojan.Dropper.MSIL.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGT23
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.FOV!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILZilla.19239 (B)?

IL:Trojan.MSILZilla.19239 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment