Trojan

Should I remove “IL:Trojan.MSILZilla.RedLine.22492”?

Malware Removal

The IL:Trojan.MSILZilla.RedLine.22492 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.RedLine.22492 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the RedLine malware family
  • Binary compilation timestomping detected

How to determine IL:Trojan.MSILZilla.RedLine.22492?


File Info:

name: 4AF397BE57285A33B97A.mlw
path: /opt/CAPEv2/storage/binaries/ee2f94c7b4a5e2306cc938b2ed056290b4b341e2749a45c7a9364d09102232f2
crc32: 5A8A1A2D
md5: 4af397be57285a33b97a341fac1682db
sha1: af921fdbc960eaadd6eceebea2de01dde65d162e
sha256: ee2f94c7b4a5e2306cc938b2ed056290b4b341e2749a45c7a9364d09102232f2
sha512: ae65f9968de6625f8e8481437a29f124ee9151fd6d92e240c30821892ca9dea2b673f3b3ccabd5716fa163b2c1e8245dc51961f157666fe6aef5af46572f5644
ssdeep: 1536:YPqUPY5gyWjddJg3Jf+bD1gq582DNODNPNDCDNyiupjyCoDN1DvKDNPiYJ7GbsSV:vX+hmB+SpCwn19ELTdbjyIP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2933A94A3CC8A16E7BD4A349475115C83F4FA537922E78F0EC964DA2E72FC466107F2
sha3_384: a94980ca32b9e5c805b5ab8e825df7c621b0704e6ad2e5c0268041d67348df6a2ce87709aeeab23d4e3fc7d6a20a907f
ep_bytes: ff25002040006100750074006f006600
timestamp: 2053-07-31 00:17:33

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Chaliced.exe
LegalCopyright:
OriginalFilename: Chaliced.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

IL:Trojan.MSILZilla.RedLine.22492 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanIL:Trojan.MSILZilla.RedLine.22492
ClamAVWin.Trojan.Redline-9938775-1
FireEyeGeneric.mg.4af397be57285a33
ALYacIL:Trojan.MSILZilla.RedLine.22492
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderIL:Trojan.MSILZilla.RedLine.22492
AvastWin32:PWSX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.RedLine.22492
EmsisoftIL:Trojan.MSILZilla.RedLine.22492 (B)
DrWebTrojan.PWS.StealerNET.125
VIPREIL:Trojan.MSILZilla.RedLine.22492
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan-Stealer.Redline.G
AviraHEUR/AGEN.1234971
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.3CE9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.AF.C5226473
Acronissuspicious
McAfeeGenericRXQA-AF!4AF397BE5728
VBA32Trojan.MSIL.InfoStealer.gen.U
MalwarebytesSpyware.PasswordStealer.MSIL
RisingStealer.Agent!1.DC63 (CLASSIC)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DFY!tr
BitDefenderThetaGen:NN.ZemsilF.34646.fm0@aamDLIb
AVGWin32:PWSX-gen [Trj]

How to remove IL:Trojan.MSILZilla.RedLine.22492?

IL:Trojan.MSILZilla.RedLine.22492 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment