Trojan

Trojan.MSIL.XMU removal

Malware Removal

The Trojan.MSIL.XMU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.XMU virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan.MSIL.XMU?


File Info:

name: AED4EA1C3D7F685F6A08.mlw
path: /opt/CAPEv2/storage/binaries/def1919040e1a435a6dcc67b11486a90726218a964cc4577f1d33433fb252126
crc32: F4387B44
md5: aed4ea1c3d7f685f6a0893d26614e0c2
sha1: 713e9db349f7ee87e1561f81b61b4b9dddd7bdbb
sha256: def1919040e1a435a6dcc67b11486a90726218a964cc4577f1d33433fb252126
sha512: 1965c853fea52786b476e0dc92c01ef3bdf415052d2d37d0be23833207d56751bb3682d2d419b729523c7014a2a844025cdd9185da147a4bbc1d4a5127ec3d8e
ssdeep: 12288:fI1gttBE923JOj9AwaISK59FRHpJb+I+9ZFyfuXEEzjXQfu+B+xX3rXUj59bCC4:f4qtqmJw59FRH3b+femlzrQv+tqhi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A1522307A44FD59D93C9536991BA3B70FA23DE5881426EB33C7B38EEB3F680111A564
sha3_384: 825cd01c40182228fde8ef16ac82ef61e16f7362fcc2db1c3ee7c075c9650506aae3f47298ce040c68f1210606c62f33
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-02-15 19:07:35

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Z@K47FG4
FileDescription: Z@K47FG
FileVersion: 8.0.4.4
InternalName: Ik76tttZ.exe
LegalCopyright: Copyright © 2825
LegalTrademarks:
OriginalFilename: Ik76tttZ.exe
ProductName: Z@K47FG4O
ProductVersion: 8.0.4.4
Assembly Version: 1.7.3.0

Trojan.MSIL.XMU also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.XMU
SkyhighGenericRXAZ-EX!AED4EA1C3D7F
McAfeeGenericRXAZ-EX!AED4EA1C3D7F
Cylanceunsafe
ZillyaTrojan.XMU.Win32.49
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.296cf8ac
K7GWTrojan ( 0051b9181 )
K7AntiVirusTrojan ( 0051b9181 )
ArcabitTrojan.MSIL.XMU
BitDefenderThetaGen:NN.ZemsilF.36680.4m0@aqZYWum
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.IIS
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.MSIL.XMU
NANO-AntivirusTrojan.Win32.GenKryptik.eliczc
SUPERAntiSpywareAdware.Tuto4PC/Variant
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Jmnw
EmsisoftTrojan.MSIL.XMU (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebAdware.Eorezo.947
VIPRETrojan.MSIL.XMU
SophosMal/Kryptik-BF
IkarusTrojan.MSIL.Crypt
VaristW32/S-6690333a!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.MSIL.Injector.QTZ@6mgpxg
MicrosoftSoftwareBundler:MSIL/Wizrem
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.MSIL.XMU
GoogleDetected
AhnLab-V3PUP/Win32.Wizrem.C1814721
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.A911 (CLASSIC)
YandexTrojan.Agent!xCDmVgvd57o
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.QTZ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.349f7e
DeepInstinctMALICIOUS

How to remove Trojan.MSIL.XMU?

Trojan.MSIL.XMU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment