Malware

MSIL/Asbit.R removal tips

Malware Removal

The MSIL/Asbit.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Asbit.R virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Asbit.R?


File Info:

name: B4AFD27DD9265321EEE8.mlw
path: /opt/CAPEv2/storage/binaries/5895458b49a83a0ba7ac7f7b9cc9b4e440e584a9ed582b57c9fd80abcc4d2ffd
crc32: 18CB3B0E
md5: b4afd27dd9265321eee8c6741254ef11
sha1: 805c9da8af4e6aa32f985e36921e4ce21f8a5a45
sha256: 5895458b49a83a0ba7ac7f7b9cc9b4e440e584a9ed582b57c9fd80abcc4d2ffd
sha512: 582cbaa588749308956c9dec5245b937efc0254c3de21848aa2b13fe50656c5552fe995cead0a47a44cda55a8ca40d861ec755ca8382b4040a455c70888283f6
ssdeep: 96:x/+Uulaj6g0PU/3tldNxzApZxk1AJt4lTisvynhW2:x/+UIaj6dUlldNaprIRGsanR
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FED1F925E6DC4239DADE4F74ADD5734103B4EBA2B4125B5D1C44010DAE01750CFB2FB5
sha3_384: 92e3fb8c2bf9fb9d8738eb1edfce8a6dd0c043a2ba511af16cc6059682ae4f1ed9b5a9b2351472dd0332241333685efe
ep_bytes: ff250020001000000000000000000000
timestamp: 2049-05-10 06:31:34

Version Info:

Translation: 0x0000 0x04b0
Comments: dXNpbmcgU3lzdGVtLlJlZmxlY3Rpb247CnB1YmxpYyBjbGFzcyBQcm9ncmFtIHsKICAgIHB1YmxpYyBQcm9ncmFtKHN0cmluZyBzLCBwYXJhbXMgb2JqZWN0W10gYXJncyl7CiAgICAgICAgQXNzZW1ibHkuTG9hZChuZXcgU3lzdGVtLk5ldC5XZWJDbGllbnQoKS5Eb3dubG9hZERhdGEocykpLkNyZWF0ZUluc3RhbmNlKCJQcm9ncmFtIiwgdHJ1ZSwgQmluZGluZ0ZsYWdzLkNyZWF0ZUluc3RhbmNlLCBudWxsLCBhcmdzLCBudWxsLCBudWxsKTsKICAgIH0KfQ==
FileDescription: aHR0cHM6Ly9yZGxpdGUuY29tLw==
FileVersion: 1.0.0.0
InternalName: System.dll
LegalCopyright:
OriginalFilename: System.dll
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Asbit.R also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Agent.a!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoaderNET.465
MicroWorld-eScanTrojan.GenericKDZ.99166
CAT-QuickHealPUA.MFC.S28621403
SkyhighBehavesLike.Win32.Generic.xt
McAfeeGenericRXUB-IG!B4AFD27DD926
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.99166
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:MSIL/Asbit.170cf1d3
K7GWTrojan ( 00597da81 )
K7AntiVirusTrojan ( 00597da81 )
ArcabitTrojan.Generic.D1835E
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Asbit.R
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Cerbu-9965437-0
KasperskyHEUR:Trojan-Downloader.MSIL.Agent.gen
BitDefenderTrojan.GenericKDZ.99166
NANO-AntivirusTrojan.Win32.Redcap.jsgseg
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:TrojanX-gen [Trj]
RisingBackdoor.FastDesktop!1.E02A (CLASSIC)
EmsisoftTrojan.GenericKDZ.99166 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
ZillyaTrojan.Asbit.Win32.162
SophosTroj/DwnLd-AEP
IkarusTrojan.MSIL.Asbit
JiangminTrojanDownloader.MSIL.ancb
VaristW32/MSIL_Tiny.AG.gen!Eldorado
AviraTR/Dropper.MSIL.Gen
Antiy-AVLGrayWare/MSIL.Regasm.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Agent.gen
GDataTrojan.GenericKDZ.99166
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.R512047
Acronissuspicious
VBA32Trojan.MSIL.RdLoader.Heur
Cylanceunsafe
TencentTrojan.Win32.Asbit.yd
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.187020364.susgen
FortinetMSIL/Tedy.1448!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove MSIL/Asbit.R?

MSIL/Asbit.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment