Trojan

IL:Trojan.MSILZilla.Azorult.1690 (B) (file analysis)

Malware Removal

The IL:Trojan.MSILZilla.Azorult.1690 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.Azorult.1690 (B) virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine IL:Trojan.MSILZilla.Azorult.1690 (B)?


File Info:

name: D12C2A2402BBB27CA22F.mlw
path: /opt/CAPEv2/storage/binaries/5d1928805cfd560f75e451b69bc8ff0165dfca3dfda2aeea5bdf38e744ce9a34
crc32: 4ABCB129
md5: d12c2a2402bbb27ca22f1b039dd0f3c7
sha1: ae2c406c7d2ab9525ab3e8830030f808512b7d64
sha256: 5d1928805cfd560f75e451b69bc8ff0165dfca3dfda2aeea5bdf38e744ce9a34
sha512: 3be8dcebc901013d1a355acf49f8732941dde7352ef3beaae8436f06247b3162a5479ae2970993a11c149cc774750319e28986db0b539d2aca853c9a55bacd6d
ssdeep: 6144:7ol5oStYWdKWQUpk7KAx9ou1WTBywOjbYcpr4+4lwVjstTK3lZX:g6YJdFm7Ku38TBywktpLjd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1837423318220D1A3E8E7467C0463E7837ADE764A532452BEB4766903EB27BF471937D2
sha3_384: d6ea2dd03b7706d4bd8e353eca2329627b2e9bed328d348902e4311499d1a1db62412c54c406c0c54714597e4af25aec
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-27 06:28:14

Version Info:

Translation: 0x0000 0x04b0
Comments: Realtek Semiconductor Corp.
CompanyName: Realtek Semiconductor Corp.
FileDescription: Realtek Semiconductor Corp.
FileVersion: 3.2.0.6
InternalName: dosnet.exe
LegalCopyright: Copyright (C) 2018 Realtek Semiconductor Corp.
OriginalFilename: dosnet.exe
ProductName: Realtek Semiconductor Corp.
ProductVersion: 3.2.0.6
Assembly Version: 3.2.0.6

IL:Trojan.MSILZilla.Azorult.1690 (B) also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanIL:Trojan.MSILZilla.Azorult.1690
ClamAVWin.Packed.Razy-7334624-0
FireEyeGeneric.mg.d12c2a2402bbb27c
McAfeePWS-FCUT!D12C2A2402BB
MalwarebytesTrojan.Crypt.STB.Generic
VIPREIL:Trojan.MSILZilla.Azorult.1690
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056052a1 )
K7GWTrojan ( 0056052a1 )
Cybereasonmalicious.402bbb
CyrenW32/MSIL_Troj.VM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.SZH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Azorult.gen
BitDefenderIL:Trojan.MSILZilla.Azorult.1690
AvastWin32:CrypterX-gen [Trj]
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:1ZoZHA0Qodv/QP/N+PGIjw)
Ad-AwareIL:Trojan.MSILZilla.Azorult.1690
SophosTroj/MSIL-RDY
DrWebTrojan.Inject3.26307
Trapminemalicious.high.ml.score
EmsisoftIL:Trojan.MSILZilla.Azorult.1690 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1216690
MAXmalware (ai score=83)
GDataIL:Trojan.MSILZilla.Azorult.1690
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C3459566
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34606.vm0@a0PK0Tp
ALYacIL:Trojan.MSILZilla.Azorult.1690
TencentTrojan-Psw.Msil.Azorult.zb
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.SZH!tr
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove IL:Trojan.MSILZilla.Azorult.1690 (B)?

IL:Trojan.MSILZilla.Azorult.1690 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment