Trojan

IL:Trojan.MSILZilla.6508 removal guide

Malware Removal

The IL:Trojan.MSILZilla.6508 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.6508 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine IL:Trojan.MSILZilla.6508?


File Info:

crc32: 53248AA7
md5: 710638ad437a2ea199dac48a6cd3669c
name: 710638AD437A2EA199DAC48A6CD3669C.mlw
sha1: 459f007de4d538afc440892a3f26f4ed36c91570
sha256: 37f92af2352645fe9be9bd00bdf610d760c3ba229a07b1bd0484651933032928
sha512: 4cfc2792a12a104be1a4f228d883b748aabba29995543eb55980b137647c83bc0df66ee92ad981395c0753cba40e0f01d263f61a07684272098f772e9a2b0ea4
ssdeep: 3072:IurlxKcLBZde2vBVQF4EWjFRA229YvepcCBKX7pV:TrlzbdeAVQF4EWx92iepcCBKr
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: vNOyDtV6Jhq3Ovyv8MrS2fK7hYn0tu
Assembly Version: 0.5.8.3
InternalName: assemblychange.exe
FileVersion: 3.7.0.8
CompanyName: kf4pGGkX0dfZVuNk9ue52LQ8od51lS
LegalTrademarks: GSIQHUAzM3kepDlVfuSiwMVAxmx4zf
Comments: JBrtUpdMkpHaUCmuded6c9aunEOi5y
ProductName: PMb84oE3B0o2gvBM754j2QftGNRssz
ProductVersion: 3.7.0.8
FileDescription: uBHuErmeu1MUP2NOpD7Mh2cXwgTR0y
OriginalFilename: assemblychange.exe

IL:Trojan.MSILZilla.6508 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.27474
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Bladabindi.AL3
ALYacIL:Trojan.MSILZilla.6508
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d437a2
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AT
ZonerTrojan.Win32.85324
APEXMalicious
AvastMSIL:KillAV-B [Trj]
ClamAVWin.Dropper.njRAT-7400469-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.6508
NANO-AntivirusTrojan.Win32.MlwGen.dckdxu
MicroWorld-eScanIL:Trojan.MSILZilla.6508
Ad-AwareIL:Trojan.MSILZilla.6508
SophosML/PE-A + Mal/Bladabi-P
ComodoTrojWare.MSIL.Bladabindi.W@8alt75
BitDefenderThetaGen:NN.ZemsilF.34266.lm0@aCzXP2
TrendMicroBKDR_BLADABI.SMF
McAfee-GW-EditionPWS-FDEC!710638AD437A
FireEyeGeneric.mg.710638ad437a2ea1
EmsisoftIL:Trojan.MSILZilla.6508 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aztew
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.831312
MicrosoftPWS:MSIL/Mintluks.A
ArcabitIL:Trojan.MSILZilla.D196C
GDataMSIL.Backdoor.Motnav.A
AhnLab-V3Trojan/Win32.Generic.C263497
McAfeePWS-FDEC!710638AD437A
MAXmalware (ai score=87)
VBA32Trojan.Downloader
MalwarebytesHackTool.Agent.ACGen
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BLADABI.SMF
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.Agent!mYCeBpNVFBg
IkarusWorm.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SpyPSW.AVQ!tr
AVGMSIL:KillAV-B [Trj]
Paloaltogeneric.ml

How to remove IL:Trojan.MSILZilla.6508?

IL:Trojan.MSILZilla.6508 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment