Malware

MSIL.Starter.2 removal tips

Malware Removal

The MSIL.Starter.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL.Starter.2 virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL.Starter.2?


File Info:

name: AC2758AC6F65B2A758EC.mlw
path: /opt/CAPEv2/storage/binaries/68e16b9a901d3c6946f1b14726ab94a9909b2cd448ba6e6f941816af65a75494
crc32: E6B1FC0A
md5: ac2758ac6f65b2a758ecef81c5696346
sha1: 344ac6eb4e32014e353c6c2518b07e371a6c3e77
sha256: 68e16b9a901d3c6946f1b14726ab94a9909b2cd448ba6e6f941816af65a75494
sha512: 551f6c1be076a559ae96378628f7a18641e8e889f8b49b997c8e0f03bfb930161416559ed51f10a1d00ba8b6aa85bd731853de321ec392413756d208b5c29792
ssdeep: 96:AojiLtou0nnnStMcE2MYlnlYJnLLPL0KffAE80uRRXmmhjkJzNt:A6u8nSPVVnlYJLLLTr2ir
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BD1F92197F04273CBBF07770DA356011775D604EEABABAF2454A37B4E436488563372
sha3_384: f0315db43d33cf484fb152c08530b1db5018c0a30a013482af4beaef166b7b1e8b225768d3adbc09c06ef72e4389df79
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-02-09 17:41:16

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: svhost.exe
LegalCopyright:
OriginalFilename: svhost.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL.Starter.2 also known as:

LionicRiskware.MSIL.Tpyn.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSIL.Starter.2
FireEyeGeneric.mg.ac2758ac6f65b2a7
McAfeeTrojan-FNJO!AC2758AC6F65
Cylanceunsafe
ZillyaTrojan.Starter.Win32.40169
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Launcher.37a60946
K7GWTrojan ( 0058c9f81 )
K7AntiVirusTrojan ( 0058c9f81 )
CyrenW32/MSIL_Kryptik.EIF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Starter.BG
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.MSIL.Starter.gen
BitDefenderGen:Variant.MSIL.Starter.2
AvastWin32:Malware-gen
TencentMsil.Risk.Tpyn.Ugil
TACHYONTrojan/W32.DN-Agent.6656.ER
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1306578
VIPREGen:Variant.MSIL.Starter.2
TrendMicroTROJ_GEN.R002C0DGA23
McAfee-GW-EditionTrojan-FNJO!AC2758AC6F65
EmsisoftTrojan.Crypt (A)
IkarusTrojan.MSIL.Starter
GDataGen:Variant.MSIL.Starter.2
AviraHEUR/AGEN.1306578
Antiy-AVLRiskWare[RiskTool]/MSIL.Tpyn
XcitiumTrojWare.MSIL.Starter.BG@7ez8ct
ArcabitTrojan.MSIL.Starter.2
ZoneAlarmVHO:Trojan.MSIL.Starter.gen
MicrosoftTrojan:MSIL/Launcher.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Launcher.C4530198
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.36302.am0@aeVpJpn
ALYacGen:Variant.MSIL.Starter.2
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGA23
RisingTrojan.Starter!8.2BC (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.50078!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove MSIL.Starter.2?

MSIL.Starter.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment