Trojan

About “Trojan.AntiVM.MSIL” infection

Malware Removal

The Trojan.AntiVM.MSIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AntiVM.MSIL virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the LimeRAT malware family

How to determine Trojan.AntiVM.MSIL?


File Info:

name: 8A469A7CCBEA7B4784B7.mlw
path: /opt/CAPEv2/storage/binaries/ad3444ddf508c4e7b2363452dccf0fc3bf0d60d84f80e5fb038665a9bca23fa0
crc32: 560995D1
md5: 8a469a7ccbea7b4784b786fd2eafb41e
sha1: 4c2e2a964e95b9e5141cbb85187813600ab35531
sha256: ad3444ddf508c4e7b2363452dccf0fc3bf0d60d84f80e5fb038665a9bca23fa0
sha512: 9e4c5a6418d3fc07b8576fe01f13048f2d9faa8b93cac63edf63603a801f62451b684a3884d40e1561d70cceda923707c1b94a0a830a5ced0bf19767d48b4ae0
ssdeep: 384:8E0WnRVOKpmvzpoKrfajhFSNqjyB0xpDFVvDuNrCeJE3WN5T70jTZMQeHFS65Xrq:JOjiKridFdjakJlk5NQqQO2lY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133D26C043FE2635CC2ED9AB54FB2352A0EB1561B4637DB1C0CC8A4971A63BC68B45BF1
sha3_384: 07660947a7cd6fa3e33abcc82232c9a5734e9529ead836eafb19648c3b15ee2f36da00f7df64decea0a7dea6733ae445
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-09 13:23:27

Version Info:

0: [No Data]

Trojan.AntiVM.MSIL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.7623
FireEyeGeneric.mg.8a469a7ccbea7b47
CAT-QuickHealTrojan.MsilFC.S19436131
ALYacIL:Trojan.MSILZilla.7623
MalwarebytesTrojan.AntiVM.MSIL
ZillyaTrojan.Disfa.Win32.54455
K7AntiVirusTrojan ( 005684c61 )
K7GWTrojan ( 005684c61 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitIL:Trojan.MSILZilla.D1DC7
BitDefenderThetaGen:NN.ZemsilF.34084.biW@amgG2Vi
CyrenW32/Tasker.A.gen!Eldorado
SymantecTrojan.LimeRat
ESET-NOD32a variant of MSIL/Agent.BPK
APEXMalicious
ClamAVWin.Malware.Barys-6836745-0
KasperskyHEUR:Trojan.MSIL.Tasker.gen
BitDefenderIL:Trojan.MSILZilla.7623
AvastWin32:KeyloggerX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.7623
EmsisoftIL:Trojan.MSILZilla.7623 (B)
DrWebTrojan.Siggen7.63254
TrendMicroCoinminer.MSIL.LIMERAT.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
SophosML/PE-A
IkarusTrojan.MSIL.Agent
JiangminTrojan.MSIL.oupm
AviraTR/Spy.Gen8
MicrosoftBackdoor:Win32/LimeRat.YA!MTB
GDataIL:Trojan.MSILZilla.7623
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/LimeRAT.Exp
Acronissuspicious
McAfeeGenericRXGM-OD!8A469A7CCBEA
MAXmalware (ai score=81)
CylanceUnsafe
TrendMicro-HouseCallCoinminer.MSIL.LIMERAT.SMA
RisingBackdoor.LimeRat!1.B863 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.SWO!tr
AVGWin32:KeyloggerX-gen [Trj]
Cybereasonmalicious.ccbea7
PandaTrj/GdSda.A

How to remove Trojan.AntiVM.MSIL?

Trojan.AntiVM.MSIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment