Trojan

suspected of Trojan.MSIL.InfoStealer.D (file analysis)

Malware Removal

The suspected of Trojan.MSIL.InfoStealer.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What suspected of Trojan.MSIL.InfoStealer.D virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine suspected of Trojan.MSIL.InfoStealer.D?


File Info:

name: 222EC55150E89F4C91DB.mlw
path: /opt/CAPEv2/storage/binaries/b164b6d31613a4dab5ea57d77e5806023c0be75c29b5a9b4bc798e5323e8a9a6
crc32: 3CCB4462
md5: 222ec55150e89f4c91db93407219ef57
sha1: 87b95ea97847ae3d2d240ef79cde52e3cb44d764
sha256: b164b6d31613a4dab5ea57d77e5806023c0be75c29b5a9b4bc798e5323e8a9a6
sha512: 60e654018a170ea61ced936f7e9cb230bfcc78865e786a377a8dc7434553bc7fa144d333027864a6d64a7c4ad61eeff4cbd98c95cf8e0746baadf1d440d24dc1
ssdeep: 1536:Bw2zCE9cLcAuJiXsNZth4MfMVFU7d23V3rx2egbSQi5kXL7weBDY6Tiz:i2zCv6+sNB4AYV3V74egbDi50L7we5YN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AE934B7C23D88E28D1FD4739B87502150BF5A10A6513FB5D8F89A8DF3E22BA15906B73
sha3_384: 105bc7645b9bebbee8957e627d3e1561805edef0b11cac4e24f41715fecb07a2885f73d026e418fdef58ea75982a1aa2
ep_bytes: ff250020400000000000000000000000
timestamp: 2056-11-24 09:14:44

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: client
FileVersion: 1.0.0.0
InternalName: client.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: client.exe
ProductName: client
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

suspected of Trojan.MSIL.InfoStealer.D also known as:

BkavW32.AIDetectNet.01
DrWebTrojan.PWS.DiscordNET.52
MicroWorld-eScanIL:Trojan.MSILMamut.2835
FireEyeGeneric.mg.222ec55150e89f4c
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
VIPREIL:Trojan.MSILMamut.2835
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.150e89
BitDefenderThetaGen:NN.ZemsilF.34806.fm0@a4OpMpc
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.AES
ClamAVWin.Packed.Msilmamut-9952939-0
KasperskyTrojan-Banker.MSIL.Evital.gen
BitDefenderIL:Trojan.MSILMamut.2835
AvastWin32:SpywareX-gen [Trj]
RisingStealer.Agent!1.D361 (CLASSIC)
Ad-AwareIL:Trojan.MSILMamut.2835
EmsisoftIL:Trojan.MSILMamut.2835 (B)
F-SecureHeuristic.HEUR/AGEN.1203031
SentinelOneStatic AI – Malicious PE
SophosMal/Stealer-G
AviraHEUR/AGEN.1203031
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan-Banker.MSIL.Evital.gen
GDataMSIL.Trojan-Stealer.DiscordStealer.D
CynetMalicious (score: 100)
Acronissuspicious
VBA32suspected of Trojan.MSIL.InfoStealer.gen.D
ALYacIL:Trojan.MSILMamut.2835
MalwarebytesSpyware.PasswordStealer.MSIL
APEXMalicious
YandexTrojan.PWS.Evital!kFI77eO7bR0
MAXmalware (ai score=82)
AVGWin32:SpywareX-gen [Trj]

How to remove suspected of Trojan.MSIL.InfoStealer.D?

suspected of Trojan.MSIL.InfoStealer.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment