Malware

How to remove “MSIL.Mensa.16”?

Malware Removal

The MSIL.Mensa.16 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL.Mensa.16 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
ocsp.verisign.com
csc3-2009-2-crl.verisign.com

How to determine MSIL.Mensa.16?


File Info:

crc32: BB7A881F
md5: 4b6ed3e78843e0dddf43aa2ecb60575f
name: 4B6ED3E78843E0DDDF43AA2ECB60575F.mlw
sha1: 0652ac07b18a822465bccce5f76580c5e7150ff6
sha256: 5801631b74c2319cd69b6fbe02ec6b7220f14eafb6e923f40b8ba05e014773fa
sha512: 3a47c357dd75b37692367f62eb781a0e0fbe357b472c700ad83a01ac27d49bf339d3bf6ac1dd898ab30426bab17df60ba8fadc73b8360f9bf885ca9b547f4da6
ssdeep: 24576:aczFj91EQF9dQvUFZjtm4HFOgoqspffpb1oQ57UI22YIV4cFrxj1CcjA:acN9dQvUbjEkFJo/f1CQ5Aer3xCoA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL.Mensa.16 also known as:

K7AntiVirusTrojan ( 00507e501 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader17.15248
CAT-QuickHealTrojan.BlockFC.S15903951
ALYacGen:Variant.MSIL.Mensa.16
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.37539
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00507e501 )
Cybereasonmalicious.78843e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.INN
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.jynm
BitDefenderGen:Variant.MSIL.Mensa.16
NANO-AntivirusTrojan.Win32.Blocker.ewswzn
MicroWorld-eScanGen:Variant.MSIL.Mensa.16
TencentMalware.Win32.Gencirc.10bbedb1
Ad-AwareGen:Variant.MSIL.Mensa.16
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34796.KnX@ayn2SAki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.4b6ed3e78843e0dd
EmsisoftGen:Variant.MSIL.Mensa.16 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.gqa
AviraHEUR/AGEN.1100384
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.MSIL.Mensa.16
GDataGen:Variant.MSIL.Mensa.16
McAfeeArtemis!4B6ED3E78843
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3145255586
PandaTrj/GdSda.A
YandexTrojan.Kryptik!+I5mavrprs0
IkarusTrojan.Msil
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.9EF98!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASSQA

How to remove MSIL.Mensa.16?

MSIL.Mensa.16 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment