Trojan

IL:Trojan.MSILZilla.5667 (B) removal guide

Malware Removal

The IL:Trojan.MSILZilla.5667 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.5667 (B) virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine IL:Trojan.MSILZilla.5667 (B)?


File Info:

name: 29B73002D5AF053424D9.mlw
path: /opt/CAPEv2/storage/binaries/e89e8d20c2c47d0976e8cf48018bf85c4894d98cf720c714a9d010af242035ce
crc32: 6A186678
md5: 29b73002d5af053424d939657ad99c87
sha1: 44612fd04a07e9001be0113b19b544026f186384
sha256: e89e8d20c2c47d0976e8cf48018bf85c4894d98cf720c714a9d010af242035ce
sha512: 0b82abd158244a4d8637ccd72c4fdec5d0ddc6a338e31d6d9b905a3365376737d7a125db5728ac9696941afeda4731259eef9a2e6ee32572dd52f74da5c87d1b
ssdeep: 1536:gozOlhfllS1YcqLB4eQrVPb7aIZabc/cpLb:tOlRllS1YFB4eQtJU0SLb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15533830177FD0218F6FF7F75ADBA94904676BA669D31DA0D0888548E1AF1F808A21F73
sha3_384: 64b9c6fc564bc535bd5f13501650ce6f9b7bdc6807ebf642a44556ee89a1fd7754cda2bf92be4429498423f74d609a7f
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-04-21 15:07:42

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: DCOMInterfacesWorm
FileVersion: 1.0.0.0
InternalName: CymulateDCOMInterfacesWorm.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: CymulateDCOMInterfacesWorm.exe
ProductName: DCOMInterfacesWorm
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

IL:Trojan.MSILZilla.5667 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.5667
FireEyeGeneric.mg.29b73002d5af0534
CAT-QuickHealTrojan.MsilheracleFC.S23213255
McAfeeGenericRXQE-GM!29B73002D5AF
K7AntiVirusRiskware ( 005672271 )
K7GWRiskware ( 005672271 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Riskware.Cymulate.A
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.MSIL.Cymulate.gen
BitDefenderIL:Trojan.MSILZilla.5667
AvastWin32:Malware-gen
Ad-AwareIL:Trojan.MSILZilla.5667
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionGenericRXQE-GM!29B73002D5AF
EmsisoftIL:Trojan.MSILZilla.5667 (B)
AviraHEUR/AGEN.1136824
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitIL:Trojan.MSILZilla.D1623
GDataIL:Trojan.MSILZilla.5667
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4521545
BitDefenderThetaGen:NN.ZemsilF.34294.dm0@aupbCSl
ALYacIL:Trojan.MSILZilla.5667
MAXmalware (ai score=80)
VBA32Trojan.MSIL.gen.15
MalwarebytesRiskWare.Cymulate
FortinetRiskware/Cymulate.A
AVGWin32:Malware-gen
Cybereasonmalicious.2d5af0
PandaTrj/GdSda.A

How to remove IL:Trojan.MSILZilla.5667 (B)?

IL:Trojan.MSILZilla.5667 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment