Trojan

IL:Trojan.MSILZilla.4911 (B) removal guide

Malware Removal

The IL:Trojan.MSILZilla.4911 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.4911 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • CAPE detected the NanoCore malware family
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine IL:Trojan.MSILZilla.4911 (B)?


File Info:

name: 040BADFDC84605E123DB.mlw
path: /opt/CAPEv2/storage/binaries/f088e990b619e54ce71335a501a8715930e7023433f50d913aeb898c8cd3ec4f
crc32: 22AB98FA
md5: 040badfdc84605e123db963a3624dc53
sha1: d6a4d952858c0bc48d1b062e5c4f4b76f390ff01
sha256: f088e990b619e54ce71335a501a8715930e7023433f50d913aeb898c8cd3ec4f
sha512: cb0b083d5eaf2d8b125c1efa7dc774875baaa98d1229ce3c9c6ed054109674f1f4a086621c6ea51b665c7d52842141a09cd3e99da6da95e960d30f0aaa52b727
ssdeep: 6144:Lz6gyL/cU2rqDgCC/Dkv68JlIDiDkLocxI:igyL/cULDkD5nDPoyI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B14423448E1430FFD6B7A73121A2653AA7C71EEA0F257A631E1FC14528377A2FBE1581
sha3_384: d2aaca31ea6fe772a9494110b21035aa68cfbe96853b1093b71dddec40dedbd415f982ee3afbebb682db6401dfba0d01
ep_bytes: 60be004044008dbe00d0fbff5783cdff
timestamp: 2011-07-03 09:05:04

Version Info:

0: [No Data]

IL:Trojan.MSILZilla.4911 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealVirTool.Vbinder.CO5
McAfeeGenericRXAA-CZ!75DB0B4E4111
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3df1 )
K7GWTrojan ( 0055e3df1 )
Cybereasonmalicious.dc8460
BaiduWin32.Trojan-Dropper.Binder.m
CyrenW32/Renos.TYAH-0409
ESET-NOD32Win32/TrojanDropper.Binder.NBH
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Tool.Binder-6750589-0
KasperskyHackTool.Win32.Binder.bs
BitDefenderIL:Trojan.MSILZilla.4911
NANO-AntivirusTrojan.Win32.NanoBot.hmqoyu
ViRobotTrojan.Win32.A.Swisyn.49120[UPX]
MicroWorld-eScanIL:Trojan.MSILZilla.4911
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazq5Sm3U+5jXH4AQOjt9x/CH)
Ad-AwareIL:Trojan.MSILZilla.4911
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
DrWebTrojan.MulDrop2.39589
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroBKDR_NOANCOOE.SM
FireEyeGeneric.mg.040badfdc84605e1
EmsisoftIL:Trojan.MSILZilla.4911 (B)
IkarusTrojan.SuspectCRC
GDataIL:Trojan.MSILZilla.4911
JiangminHackTool.Binder.bh
AviraTR/Dropper.MSIL.Gen7
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASBOL.C91
ArcabitIL:Trojan.MSILZilla.D132F
SUPERAntiSpywareTrojan.Agent/Gen-Fynloski
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.HackTool.C233787
VBA32Binder.Celesty
ALYacIL:Trojan.MSILZilla.4911
MalwarebytesTrojan.Binded
TrendMicro-HouseCallBKDR_NOANCOOE.SM
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!o/ixl7L2Afs
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/CoinMiner.NBH!tr
BitDefenderThetaAI:Packer.7DF2738B1F
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureHackTool.W32.Binder.bs

How to remove IL:Trojan.MSILZilla.4911 (B)?

IL:Trojan.MSILZilla.4911 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment