Trojan

What is “IL:Trojan.MSILZilla.20940 (B)”?

Malware Removal

The IL:Trojan.MSILZilla.20940 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.20940 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine IL:Trojan.MSILZilla.20940 (B)?


File Info:

name: 7C3EADFECFE561377046.mlw
path: /opt/CAPEv2/storage/binaries/e9656093c6dad5244557f370626816b9bd2e0ebf089ad33d8f6c3645b42a504b
crc32: 6DACBF8B
md5: 7c3eadfecfe56137704664a9cbed3544
sha1: 7f027de769d54625cf72a431d2cc7c5edc991ff4
sha256: e9656093c6dad5244557f370626816b9bd2e0ebf089ad33d8f6c3645b42a504b
sha512: 28bec184307674ac4ff42decf5c7bf80ecf7152974b64da3694eefd06fb05579903d5fbe0bcbf2e1f2f2c30d2d63ca4758a2d3c88a4a860f94a23f776a82d9ae
ssdeep: 768:8hq8Dql60x8tYcFwVc6KW8tYcFwVc6Kl61tYcFwVc6K:8k8+lTAwVclWAwVcll6dwVcl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101E2E605A7C48571D3BA56B76DB29381CB32E99B5C668B6F388C010D3F7224183B3BE5
sha3_384: 48c7cfdc8db94e5d80fa3afbf2a76bede49e1e15b715b8f8fac6f40fa8ff6895a61b345cf06760f4658b30d76cfd5de3
ep_bytes: ff250020400000000000000000000000
timestamp: 2094-01-01 13:56:05

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: RubberDucky_Crypt0r
FileVersion: 1.0.0.0
InternalName: RubberDucky_Crypt0r.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: RubberDucky_Crypt0r.exe
ProductName: RubberDucky_Crypt0r
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

IL:Trojan.MSILZilla.20940 (B) also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.20940
FireEyeGeneric.mg.7c3eadfecfe56137
SangforTrojan.Win32.Save.a
Cybereasonmalicious.769d54
ESET-NOD32a variant of MSIL/Filecoder.AQG
APEXMalicious
KasperskyHEUR:Trojan-Ransom.MSIL.Crypren.gen
BitDefenderIL:Trojan.MSILZilla.20940
Ad-AwareIL:Trojan.MSILZilla.20940
EmsisoftIL:Trojan.MSILZilla.20940 (B)
VIPREIL:Trojan.MSILZilla.20940
IkarusTrojan-Ransom.FileCrypter
GDataIL:Trojan.MSILZilla.20940
AviraHEUR/AGEN.1217435
MAXmalware (ai score=86)
ArcabitIL:Trojan.MSILZilla.D51CC
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
ALYacIL:Trojan.MSILZilla.20940
MalwarebytesRansom.FileCryptor.MSIL
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:8vu41Uklpw4JDLoHxGwRxQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AQG!tr
BitDefenderThetaGen:NN.ZemsilF.34742.bm0@a45PzBg

How to remove IL:Trojan.MSILZilla.20940 (B)?

IL:Trojan.MSILZilla.20940 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment