Trojan

IL:Trojan.MSILZilla.7437 removal tips

Malware Removal

The IL:Trojan.MSILZilla.7437 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.7437 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Anomalous binary characteristics

How to determine IL:Trojan.MSILZilla.7437?


File Info:

name: 415BB9336C3E48183B9A.mlw
path: /opt/CAPEv2/storage/binaries/56dd6e882c332438798aecaadb3a51a6759af6d0507d6f15083fc1df551cdcd0
crc32: B2B56CB9
md5: 415bb9336c3e48183b9a4885552b6548
sha1: 77a57405b5f03c955cfe8857cf82029602280792
sha256: 56dd6e882c332438798aecaadb3a51a6759af6d0507d6f15083fc1df551cdcd0
sha512: 0521c347cbfa119ce8772cbb3266f9ca5452bc339eaae8074c1fdf67e976f9e014780facd8151f5178a81ba9af4643c0127eabf926389dccaa9fe3914e11d5ac
ssdeep: 196608:zc1gayDpLIwYoyRsvQ5/4MjrAXPAEIOj8pzO9RpjcfQfL0iZ:zXacW1oyRbwMjtEVjlz08QiZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6B63322F6DAD035C2B222719E7AF357993D78390326C09F17C4293A5EB09927739367
sha3_384: b1e89ebe11622d530888534183fc5a5e2c6f2c7c2248f6c5c1723781f9edb9673819640ada92ea928074f5c3e0db9aef
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

IL:Trojan.MSILZilla.7437 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.415bb9336c3e4818
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
CylanceUnsafe
VIPREIL:Trojan.MSILZilla.7437
BitDefenderIL:Trojan.MSILZilla.7437
CyrenW32/MSIL_Agent.BIL.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Packed.Razy-9783140-0
KasperskyHEUR:Trojan-PSW.Multi.Disco.gen
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:dAjE9vbot3NznZ2tB0lmhA)
Ad-AwareIL:Trojan.MSILZilla.7437
EmsisoftIL:Trojan.MSILZilla.7437 (B)
F-SecureHeuristic.HEUR/AGEN.1232065
DrWebTrojan.PWS.DiscordNET.51
ZillyaDropper.Autoit.Win32.7315
TrendMicroTrojanSpy.MSIL.INFOSTEAL.SMLV
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.MSIL.PSW
GDataIL:Trojan.MSILZilla.7437 (2x)
JiangminWorm.Cridex.dq
GoogleDetected
AviraHEUR/AGEN.1232065
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASBOL.C6D6
ZoneAlarmHEUR:Trojan-PSW.Multi.Disco.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Stealer.C4089074
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34646.am0@aiLiS3c
ALYacIL:Trojan.MSILZilla.7437
TrendMicro-HouseCallTrojanSpy.MSIL.INFOSTEAL.SMLV
YandexTrojan.PWS.Agent!TtvqGjKt9os
MaxSecureTrojan.Autoit.AZA
FortinetW32/Autoit.BYM!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.36c3e4

How to remove IL:Trojan.MSILZilla.7437?

IL:Trojan.MSILZilla.7437 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment