Malware

Troj/MSILln-AE information

Malware Removal

The Troj/MSILln-AE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/MSILln-AE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Troj/MSILln-AE?


File Info:

crc32: 48E5AAF2
md5: 716b4eab6d0ae5755884643ce96b8b3c
name: tmpy46huhg9
sha1: 8655755f3fb350d921269c96ce6d3f5190f5ff8d
sha256: ce3042a91e52973326599b1d3fb755d7bda08c62e7a8f201d54ef6e33a4d5655
sha512: bf8de991a6d18a4e01115aa445b940920d8a934265994ff5da9676274d3bea6f751931394f0d030ea34ba96890374fd92583cd79e3877c6f65d534fd82a90e44
ssdeep: 6144:HB/XflK4sNag52EyDsVoLmg1dRwxCMfbRfV3oU9tFZtPa66db/DVGvYJq:HB/o40agUu5Owx5bRt3nDqbQvx
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: zATEcdDklIvkQbT.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: PokerGame
ProductVersion: 1.0.0.0
FileDescription: PokerGame
OriginalFilename: zATEcdDklIvkQbT.exe

Troj/MSILln-AE also known as:

ClamAVWin.Packed.Generickdz-8066252-0
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:MSIL/AgentTesla.43b31146
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f3fb35
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.WIR
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.34031108
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.34031108
NANO-AntivirusTrojan.Win32.Kryptik.hlfatv
MicroWorld-eScanTrojan.GenericKD.34031108
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.34031108
SophosTroj/MSILln-AE
F-SecureTrojan.TR/AD.AgentTesla.gpofr
DrWebTrojan.Siggen9.54392
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.VSNW11F20
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.716b4eab6d0ae575
EmsisoftTrojan.GenericKD.34031108 (B)
CyrenW32/MSIL_Agent.BKG.gen!Eldorado
AviraTR/AD.AgentTesla.gpofr
eGambitUnsafe.AI_Score_94%
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2074604
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
MicrosoftTrojan:MSIL/AgentTesla.YB!MTB
AhnLab-V3Trojan/Win32.Sonbokli.R340714
ALYacTrojan.GenericKD.34031108
MalwarebytesTrojan.MalPack.DFD.Generic
TrendMicro-HouseCallTROJ_FRS.VSNW11F20
YandexTrojan.Igent.bTVq7l.77
IkarusTrojan-Spy.LokiBot
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.EMOC!tr
BitDefenderThetaGen:NN.ZemsilF.34128.Am0@ae39hVi
AVGWin32:InjectorX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM03.0.EF92.Malware.Gen

How to remove Troj/MSILln-AE?

Troj/MSILln-AE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment