Trojan

IL:Trojan.MSILZilla.6674 removal

Malware Removal

The IL:Trojan.MSILZilla.6674 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.6674 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the CoinMiner04 malware family

How to determine IL:Trojan.MSILZilla.6674?


File Info:

name: 0524B5F5540E3D432AB0.mlw
path: /opt/CAPEv2/storage/binaries/7fb4bf8be9d146c0d6c200eb6bb1bd5869c6b4e031f154bb1cfc14fe01ffdc9d
crc32: 46712D50
md5: 0524b5f5540e3d432ab09b87f203dc0c
sha1: d5d8f5bcf3fb807396dbbc35ba33d691ce83e83f
sha256: 7fb4bf8be9d146c0d6c200eb6bb1bd5869c6b4e031f154bb1cfc14fe01ffdc9d
sha512: 44abde7871104bf948cd202ed2871e6005783151108c3f96470573e8003c99a996d2f0f781d6ea7594aa577bf3225dac7299c96ba5abf2799e5d2a3893b18ce5
ssdeep: 49152:UPtmnEDiOkIwU/b/WvDFSv5ZeBsYnkChayd6C0loMnjX2oKolhBKYn/:UPwED1kQuS6BsYk6dL3volTKU/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140B52352B5D000B0D5B20D394AF6A6756E3E7C205F74AB6B97C87D3D5E30280A329FA7
sha3_384: 0136d5035d23d476073d01b66200215f730a7674b4b678c08edf1fccf72d87d75d6c16ed7e1c6fe85427c32cbba1f1c4
ep_bytes: e8f2040000e98efeffff3b0dc8034300
timestamp: 2019-09-09 10:13:09

Version Info:

0: [No Data]

IL:Trojan.MSILZilla.6674 also known as:

LionicRiskware.Win32.BitMiner.1!c
DrWebTrojan.Siggen11.49734
MicroWorld-eScanIL:Trojan.MSILZilla.6674
FireEyeGeneric.mg.0524b5f5540e3d43
McAfeeArtemis!0524B5F5540E
CylanceUnsafe
ZillyaDropper.Mine.Win32.148
SangforTrojan.Win32.Generik.MBDSUGV
AlibabaTrojan:Win32/CoinMiner.ali1002002
Cybereasonmalicious.5540e3
SymantecPUA.Gen.2
ESET-NOD32a variant of Generik.MBDSUGV
TrendMicro-HouseCallTROJ_GEN.R002H0CB622
Paloaltogeneric.ml
KasperskyUDS:Trojan-Dropper.MSIL.Generic
BitDefenderIL:Trojan.MSILZilla.6674
AvastWin32:Miner-DM [Trj]
EmsisoftTrojan.CoinMiner (A)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.vc
SophosMal/Generic-S
GDataIL:Trojan.MSILZilla.6674
AviraTR/Agent.zvdgb
GridinsoftRansom.Win32.Miner.sa
ArcabitIL:Trojan.MSILZilla.D1A12
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32Trojan.Wacatac
ALYacIL:Trojan.MSILZilla.6674
MAXmalware (ai score=88)
APEXMalicious
YandexTrojan.Igent.bUS01M.22
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat.ARN.M
AVGWin32:Miner-DM [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.11234915.susgen

How to remove IL:Trojan.MSILZilla.6674?

IL:Trojan.MSILZilla.6674 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment