Trojan

IL:Trojan.MSILZilla.6980 malicious file

Malware Removal

The IL:Trojan.MSILZilla.6980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.6980 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine IL:Trojan.MSILZilla.6980?


File Info:

crc32: 9ED867C0
md5: 84b71b7623e3ce681088ea800bfcc856
name: 84B71B7623E3CE681088EA800BFCC856.mlw
sha1: 77828286cf67203b63fd1f4368226e9db53751a3
sha256: e7bdeb57de64718470c7039c914796770c940573c733ecc97e90296b26c3fcce
sha512: 359e5e04bf5729bd5ea802e3ad691a006a7e9329d35857de8e99204a8db6ebd6d2cd77adb6da16e960f3f0d0d5e427ee0612d4292d0b87db1d1200156c5cafd9
ssdeep: 1536:bW27RutYPWEBsqBJR955L+0SFCaH2pw3bv4UFZL809s7MzhLbbATOX1A/AkjH1R:RllSF72pw3bvLFxOM8YkjM
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 10.0.18362.1
InternalName: svchost.exe
FileVersion: 10.0.18362.1
CompanyName: Microsoft Corporation
Comments: Host Process for Windows Services
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.18362.1
FileDescription: Windows Update Assistant
OriginalFilename: svchost.exe

IL:Trojan.MSILZilla.6980 also known as:

K7AntiVirusTrojan ( 005647091 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.7684
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacIL:Trojan.MSILZilla.6980
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005647091 )
Cybereasonmalicious.623e3c
CyrenW32/MSIL_Bladabindi.FN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.VC
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Trojan.Razy-9778111-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.6980
MicroWorld-eScanIL:Trojan.MSILZilla.6980
Ad-AwareIL:Trojan.MSILZilla.6980
SophosML/PE-A + ATK/Blacknet-A
BitDefenderThetaGen:NN.ZemsilF.34294.im0@auIXhCk
TrendMicroBackdoor.MSIL.BLACKNET.SMDA
McAfee-GW-EditionBackDoor-FEBU!84B71B7623E3
FireEyeGeneric.mg.84b71b7623e3ce68
EmsisoftIL:Trojan.MSILZilla.6980 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fizaz
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_98%
MicrosoftBackdoor:MSIL/Blacknet.GG!MTB
GDataIL:Trojan.MSILZilla.6980
AhnLab-V3Backdoor/Win32.RL_Androm.C4127713
Acronissuspicious
McAfeeBackDoor-FEBU!84B71B7623E3
MAXmalware (ai score=83)
VBA32CIL.StupidStealth.Heur
MalwarebytesBackdoor.Bladabindi
TrendMicro-HouseCallBackdoor.MSIL.BLACKNET.SMDA
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
IkarusWorm.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.VC!tr
AVGWin32:BotX-gen [Trj]

How to remove IL:Trojan.MSILZilla.6980?

IL:Trojan.MSILZilla.6980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment