Trojan

Trojan.MSIL.Bayrob information

Malware Removal

The Trojan.MSIL.Bayrob is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Bayrob virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.MSIL.Bayrob?


File Info:

crc32: CF1718A6
md5: 0ba69dc04872abaefa74dc650d33b4ac
name: 0BA69DC04872ABAEFA74DC650D33B4AC.mlw
sha1: 03aef1ed690a6943af1b1916c85a7ee74bf8b068
sha256: 06a6f06e297a89e93223a33b0517375f043bd1b2bbd7e88867bbd6ec263ec6f7
sha512: 0182404ba810ba7e4f0f949a6620bb2d85c967158810f2e5ed9a494a9a7798664d306ff1e13142e530d4332b0f29b8915d8325c61d1a91a04039a5ae4a095c8f
ssdeep: 768:MS4tK/C0B8g6/D2J+ZO9QQh0HE7Thf3o/QhYG:WYQQSE7ThQhG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: 2012 add_BindCompleted
Assembly Version: 8.7.7.6
InternalName: BeginWrite.exe
FileVersion: 7.0.1.4
CompanyName: RetryConditionHeaderValue
LegalTrademarks: NotifyDefault
Comments: GetInitialValueChunk
ProductName: BeginWrite
ProductVersion: 8.7.7.6
FileDescription: MoveToContent
OriginalFilename: BeginWrite.exe
Translation: 0x0409 0x0514

Trojan.MSIL.Bayrob also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36425380
FireEyeTrojan.GenericKD.36425380
McAfeeRDN/GenericU
CylanceUnsafe
SangforTrojan.Win32.Woreflint.A
K7AntiVirusTrojan-Downloader ( 005788e51 )
AlibabaTrojan:MSIL/Bayrob.72548f29
K7GWTrojan-Downloader ( 005788e51 )
BitDefenderThetaGen:NN.ZemsilF.34608.bm1@aWc9o2ii
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HMB
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.Bayrob.gen
BitDefenderTrojan.GenericKD.36425380
Paloaltogeneric.ml
RisingDownloader.Agent!1.D296 (CLOUD)
Ad-AwareTrojan.GenericKD.36425380
EmsisoftTrojan.GenericKD.36425380 (B)
ComodoMalware@#d5ghiw3nr1nf
F-SecureTrojan.TR/Dldr.Agent.jibci
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.EMOTET.THCOCBA
McAfee-GW-EditionRDN/GenericU
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
GDataTrojan.GenericKD.36425380
AviraTR/Dldr.Agent.jibci
MAXmalware (ai score=86)
KingsoftWin32.Heur.KVM019.a.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D22BCEA4
AegisLabTrojan.MSIL.Bayrob.4!c
ZoneAlarmHEUR:Trojan.MSIL.Bayrob.gen
MicrosoftTrojan:Win32/Ymacco.AA06
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.MSIL.R368811
ALYacTrojan.GenericKD.36425380
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTrojanSpy.MSIL.EMOTET.THCOCBA
TencentMsil.Trojan.Bayrob.Hza
FortinetMSIL/Agent.HMB!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan.MSIL.Bayrob?

Trojan.MSIL.Bayrob removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment