Trojan

What is “IL:Trojan.MSILZilla.23204”?

Malware Removal

The IL:Trojan.MSILZilla.23204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.23204 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine IL:Trojan.MSILZilla.23204?


File Info:

name: 295CE4FAE52133ED2E9A.mlw
path: /opt/CAPEv2/storage/binaries/05fb73ed38f6a1d6dd0cd994eaa7f683c5d4ee05eee11ce5771bfcac927f210c
crc32: 9FF594B4
md5: 295ce4fae52133ed2e9affc00656d9f0
sha1: f8efa3692c2d56ea270593d8f104d939d990949b
sha256: 05fb73ed38f6a1d6dd0cd994eaa7f683c5d4ee05eee11ce5771bfcac927f210c
sha512: a74de565706530991534718a863d49c6563dc9194cbb70b99cb17be1493f5ae3e22d89e62c662f45e8fb37883f73e7649eae00b1eb6add4aac7af0aa0bef33d5
ssdeep: 24576:sfZ0sDgh3eD+ZQZFQPaVvn/8iiWitpmev3+2wPDFA2b1JdEf37vKaYyDW0ojr:scZ0+yZFQAvn/5iHpmI3+Lm2vdPQD2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F95CF2025EB561CF4BA9FB95FC4F9FA4D9BFA312529B0BA24A163454B33E00CDE1135
sha3_384: b3259711e3d7180ecbcc3e982dc594cb3bc60a1b4eed116822eb645b7d10620121888500367a2bdea8256a3648ba5750
ep_bytes: ff250020400000000000000000000000
timestamp: 2048-09-28 16:18:20

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ClinicKanesha_03
FileVersion: 1.0.0.0
InternalName: Btzejq.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: Btzejq.exe
ProductName: ClinicKanesha_03
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

IL:Trojan.MSILZilla.23204 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Agensla.i!c
tehtrisGeneric.Malware
MicroWorld-eScanIL:Trojan.MSILZilla.23204
FireEyeGeneric.mg.295ce4fae52133ed
McAfeeArtemis!295CE4FAE521
MalwarebytesMalware.AI.1940350685
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005987601 )
AlibabaTrojan:MSIL/Kryptik.bd251a19
Cybereasonmalicious.92c2d5
CyrenW32/MSIL_Troj.CJS.gen!Eldorado
SymantecMSIL.Packed.4
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.GAGZ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderIL:Trojan.MSILZilla.23204
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-QQPass.QQRob.Pzfl
Ad-AwareIL:Trojan.MSILZilla.23204
SophosMal/Generic-S
DrWebTrojan.DownLoader45.18659
McAfee-GW-EditionArtemis!Trojan
EmsisoftIL:Trojan.MSILZilla.23204 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Kryptik.zdjgb
Antiy-AVLTrojan/Generic.ASMalwS.514F
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataMSIL.Malware.Injector.JDZLMW
GoogleDetected
AhnLab-V3Trojan/Win.PWSX-gen.C5241000
Acronissuspicious
MAXmalware (ai score=82)
VBA32Malware-Cryptor.MSIL.AgentTesla.Heur
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DIK22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:wwdbjkK6XjwyhtVar5G1ug)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AGLY!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILZilla.23204?

IL:Trojan.MSILZilla.23204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment