Trojan

IL:Trojan.MSILZilla.8480 malicious file

Malware Removal

The IL:Trojan.MSILZilla.8480 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.8480 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine IL:Trojan.MSILZilla.8480?


File Info:

name: 648F06A76AA9DC830FDE.mlw
path: /opt/CAPEv2/storage/binaries/d40c6c8496b63af1e6378b7371cb46e602ae9b0e83cb532791de0d10ad30d843
crc32: 9DCFF535
md5: 648f06a76aa9dc830fde5293209eca23
sha1: fbd6e2ac19b8e959ede2e46561a60c54907d0be0
sha256: d40c6c8496b63af1e6378b7371cb46e602ae9b0e83cb532791de0d10ad30d843
sha512: 96b15840a252b6f5d5ee6e78768252f0e48d9dbdf68aebfd1389bff8541edc5db1821a03ea725acd05cea7e456779c27d7107abbb23a708e7d749fb059091459
ssdeep: 3072:/HiFCOPeisWOTJ4Q+rYlkkVIJHoUMO+Tv3kmwz:/HaPeissrYOkVVUMO+jU
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E6E33A20DFC8882FD59E077BF45357124B34E3C37905F3878B85AA996E0A35C4E54AAB
sha3_384: 1ad7b478ea766ae2281ac29156b0a8bc1905b525606af4e6091a9a191df7badcc303b640f7a12caa7f3bb95f77f0a955
ep_bytes: ff256063420000000000000000003463
timestamp: 2021-11-26 10:02:59

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Хост-процесс для служб Windows
FileVersion: 1.0.0.0
InternalName: Loader.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Loader.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

IL:Trojan.MSILZilla.8480 also known as:

LionicTrojan.Win32.Zilla.4!c
DrWebTrojan.DownLoader44.6356
MicroWorld-eScanIL:Trojan.MSILZilla.8480
McAfeeArtemis!648F06A76AA9
CylanceUnsafe
K7AntiVirusTrojan ( 005703f41 )
AlibabaTrojan:MSIL/Quasar.08d4aea2
K7GWTrojan ( 005703f41 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CLQ
TrendMicro-HouseCallTROJ_GEN.R002H09KQ21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Quasar.gen
BitDefenderIL:Trojan.MSILZilla.8480
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Msilzilla.Wogl
Ad-AwareIL:Trojan.MSILZilla.8480
SophosMal/Generic-S
F-SecureTrojan.TR/Agent.ahimu
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.648f06a76aa9dc83
EmsisoftIL:Trojan.MSILZilla.8480 (B)
SentinelOneStatic AI – Suspicious PE
GDataIL:Trojan.MSILZilla.8480
eGambitTrojan.Generic
AviraTR/Agent.ahimu
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitIL:Trojan.MSILZilla.D2120
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
ALYacIL:Trojan.MSILZilla.8480
MalwarebytesTrojan.Crypt.MSIL
APEXMalicious
IkarusTrojan.MSIL.Agent
FortinetMSIL/Agent.CLQ!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A

How to remove IL:Trojan.MSILZilla.8480?

IL:Trojan.MSILZilla.8480 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment