Trojan

How to remove “IL:Trojan.MSILZilla.7043”?

Malware Removal

The IL:Trojan.MSILZilla.7043 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.7043 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine IL:Trojan.MSILZilla.7043?


File Info:

name: A0F098FC8B44807B0B4A.mlw
path: /opt/CAPEv2/storage/binaries/4b556ee8bda12c258fce8a71511de81850551798d8f69304afa3b479f81bec07
crc32: EC6434BF
md5: a0f098fc8b44807b0b4ae845fd5746e2
sha1: 1b185d847c22514dc722c392862530a693dad7f2
sha256: 4b556ee8bda12c258fce8a71511de81850551798d8f69304afa3b479f81bec07
sha512: 04dcd8f4aeee1169e17b8f748a82155b167c47f84e8f92c7c21742da9b734bdd7d651783b309c6fb8c2d0314db9c1caf459f199a6ce42c82579a17123298bab8
ssdeep: 192:f7BEMf/GhpmaK1gMTDHx2j9BE50aX29e:TmSvbcY1X29
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A8E1B6242FED5426F4B36F785FF16382977EFA222A17AE1F1550034E4912300EE82B79
sha3_384: efcd23ace91eab04a584c8883919f7874ddfaaa02c7daf95488636b366ae2bc47b605b1a3749e3ece8efd5055291c9d7
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-07-28 08:47:59

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: payload20.exe
LegalCopyright:
OriginalFilename: payload20.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

IL:Trojan.MSILZilla.7043 also known as:

CynetMalicious (score: 100)
ALYacIL:Trojan.MSILZilla.7043
Cylanceunsafe
ZillyaTrojan.Shelma.Win32.2524
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.c8b448
CyrenW32/Razy.EL.gen!Eldorado
SymantecBackdoor.Cobalt!gm5
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.DAXJ
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Shelma.gen
BitDefenderIL:Trojan.MSILZilla.7043
MicroWorld-eScanIL:Trojan.MSILZilla.7043
AvastWin32:TrojanX-gen [Trj]
EmsisoftIL:Trojan.MSILZilla.7043 (B)
F-SecureHeuristic.HEUR/AGEN.1363042
DrWebExploit.ShellCode.46
VIPREIL:Trojan.MSILZilla.7043
McAfee-GW-EditionBehavesLike.Win32.Trojan.zt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a0f098fc8b44807b
SophosATK/TurtleLd-E
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1363042
MAXmalware (ai score=85)
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitIL:Trojan.MSILZilla.D1B83
ZoneAlarmHEUR:Trojan.MSIL.Shelma.gen
GDataIL:Trojan.MSILZilla.7043
GoogleDetected
AhnLab-V3Trojan/Win32.Kryptik.C3076693
RisingTrojan.Shelma!8.1A3D (TFE:dGZlOgxgiaZvlcnUDA)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.DAXJ!tr
BitDefenderThetaGen:NN.ZemsilF.36318.am0@a02SX7l
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove IL:Trojan.MSILZilla.7043?

IL:Trojan.MSILZilla.7043 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment