Trojan

Trojan-Downloader.MSIL removal instruction

Malware Removal

The Trojan-Downloader.MSIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.MSIL virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan-Downloader.MSIL?


File Info:

name: A3B6400F9DDDFF41B9E2.mlw
path: /opt/CAPEv2/storage/binaries/966d128f778a0e92d96f257e922540b95e5a122ae89e4477d658b8524d2e6cc3
crc32: 8F46AF8B
md5: a3b6400f9dddff41b9e2d4e4d3ecb611
sha1: f27b1212888d7e65d9de77b3b595baff92a70f95
sha256: 966d128f778a0e92d96f257e922540b95e5a122ae89e4477d658b8524d2e6cc3
sha512: d07746e3a4a7ced8472ad3e7b659e5c17b768c6ec729a27482865833dba403a8b6dd24273a0f165c13ebd7dd1bc2b88c53227f4892f37582710d19e90986fd4e
ssdeep: 48:6KzMoblyk/Sphn0i8GJYYSlao7jhdGMQhcnR2de9iuulUo+hFnqXSfbNtm:QvKgh0Tj79TQ+R2EmCokFZzNt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15591940167D88326D2BB47342AF7431222F6FA158933879E7CE9428D7D227201942FF6
sha3_384: 41457cf08a0f9a4b05b33c80b5892654940ac2621a7dc6c2d8419978e32c2bb65062cd71f76f009ea296315fca0acd6e
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-15 11:51:38

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: output.exe
LegalCopyright:
OriginalFilename: output.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan-Downloader.MSIL also known as:

LionicTrojan.MSIL.UAC.3!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.33773
MicroWorld-eScanIL:Trojan.MSILZilla.5958
FireEyeGeneric.mg.a3b6400f9dddff41
McAfeeDownloader-FCEX!A3B6400F9DDD
CylanceUnsafe
ZillyaDownloader.Tiny.Win32.22880
SangforExploit.MSIL.UAC.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaExploit:MSIL/Generic.75dc08ba
K7GWTrojan-Downloader ( 0057e3071 )
K7AntiVirusTrojan-Downloader ( 0057e3071 )
BitDefenderThetaGen:NN.ZemsilF.34160.am0@a07ORSf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.BBH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Exploit.MSIL.UAC.gen
BitDefenderIL:Trojan.MSILZilla.5958
AvastWin32:PWSX-gen [Trj]
TencentMsil.Exploit.Uac.Lmug
Ad-AwareIL:Trojan.MSILZilla.5958
EmsisoftIL:Trojan.MSILZilla.5958 (B)
TrendMicroTROJ_GEN.R002C0PAF22
McAfee-GW-EditionDownloader-FCEX!A3B6400F9DDD
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Tiny
AviraTR/Downloader.Gen9
Antiy-AVLTrojan/Generic.ASMalwS.350ABD4
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataIL:Trojan.MSILZilla.5958
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4529016
ALYacIL:Trojan.MSILZilla.5958
MAXmalware (ai score=81)
VBA32Trojan-Downloader.MSIL.gen
MalwarebytesTrojan.Downloader.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PAF22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:bgHnSOxs3UX9ShIsEndUyQ)
YandexTrojan.DL.Tiny!TvD/hs2meWk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Tiny.BBH!tr.dldr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.2888d7
PandaTrj/CI.A

How to remove Trojan-Downloader.MSIL?

Trojan-Downloader.MSIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment