Trojan

Trojan.MSIL.Basic.6.Gen (B) removal tips

Malware Removal

The Trojan.MSIL.Basic.6.Gen (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Basic.6.Gen (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.MSIL.Basic.6.Gen (B)?


File Info:

crc32: 1ABD4BCC
md5: a18e742972e5313f21b739277c03767b
name: A18E742972E5313F21B739277C03767B.mlw
sha1: 43081ffd9ea92a6c03cb3e97d2343327abb41d2a
sha256: 426606d359e196a3ca9c9c0c82acb7b98673090af4d846ddf4a5192b271a6569
sha512: b920a868cdddfc70c4dcf7482461f31fb32b2bcbd1a7ec6b6ed1c87700d27196d514fb1fea861d089fb3bf2db5ccb94fbd322937932e3d38b201c675413cab3f
ssdeep: 24576:yAkyAzwPehAIsb9mz+iyBfBxC05nbbCI9YB:LPehAIscz+igBxC0lCI94
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: STOREASSEMBLYSTATUSFLAGS.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: prj_movelex_a172423
ProductVersion: 1.0.0.0
FileDescription: prj_movelex_a172423
OriginalFilename: STOREASSEMBLYSTATUSFLAGS.exe

Trojan.MSIL.Basic.6.Gen (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.474
MicroWorld-eScanTrojan.MSIL.Basic.6.Gen
FireEyeGeneric.mg.a18e742972e5313f
CAT-QuickHealTrojan.Multi
McAfeePWS-FCTY!A18E742972E5
MalwarebytesSpyware.AgentTesla
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:MSIL/Kryptik.5dd41d5c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.972e53
BitDefenderThetaGen:NN.ZemsilF.34700.2q0@ayW87fl
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.MSIL.Basic.6.Gen
Paloaltogeneric.ml
ViRobotTrojan.Win32.Z.Woreflint.899584
TencentMsil.Trojan-spy.Noon.Lkxi
Ad-AwareTrojan.MSIL.Basic.6.Gen
EmsisoftTrojan.MSIL.Basic.6.Gen (B)
ComodoMalware@#2ihmee1xco5tg
F-SecureTrojan.TR/AD.Swotter.xjuct
McAfee-GW-EditionPWS-FCTY!A18E742972E5
SophosMal/Generic-R + Troj/Kryptik-PL
IkarusTrojan.Inject
GDataTrojan.MSIL.Basic.6.Gen
AviraTR/AD.Swotter.xjuct
MAXmalware (ai score=100)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
MicrosoftTrojan:MSIL/FormBook.SS!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4269813
ALYacTrojan.MSIL.Basic.6.Gen
CylanceUnsafe
ZonerTrojan.Win32.100063
ESET-NOD32a variant of MSIL/Kryptik.ZCH
TrendMicro-HouseCallTROJ_GEN.R06CH09LM20
YandexTrojan.Kryptik!hsVJNVXYdxQ
SentinelOneStatic AI – Malicious PE
FortinetMalicious_Behavior.SB
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Generic/HEUR/QVM03.0.1BCF.Malware.Gen

How to remove Trojan.MSIL.Basic.6.Gen (B)?

Trojan.MSIL.Basic.6.Gen (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment