Trojan

Should I remove “TrojanDownloader:MSIL/Lorozoad.A”?

Malware Removal

The TrojanDownloader:MSIL/Lorozoad.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/Lorozoad.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.up-king.com

How to determine TrojanDownloader:MSIL/Lorozoad.A?


File Info:

crc32: 00364894
md5: dcaf7ab1d8bb4e459e4ddcdf98c0e317
name: DCAF7AB1D8BB4E459E4DDCDF98C0E317.mlw
sha1: 4dab90e8a8e70ed79ca95a1cba36b5a44a2fcea2
sha256: dd213fa54f383949de6c449ac39a696dd244ad4a19643fd975eb353ba801985d
sha512: 97c6150f90008717f427ce8d18c1839966bbc9f4d38d9112e940b9f5e7f5646fa711df59a33df97d5c3026476828f7dd975b0fba341defd7f6bfa21f3bfadc7f
ssdeep: 1536:6WgQ42wGD6HhAchMMX6/pH0S8NBIPBox7ewKiHz:6qr6HhAc6MK/pUSEBja6
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: blabla.exe
FileVersion: 1.0.0.0
ProductName: media
ProductVersion: 1.0.0.0
FileDescription: media
OriginalFilename: blabla.exe

TrojanDownloader:MSIL/Lorozoad.A also known as:

MicroWorld-eScanGen:Variant.Zusy.242060
FireEyeGeneric.mg.dcaf7ab1d8bb4e45
McAfeeTrojan-FNCL!DCAF7AB1D8BB
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Zusy.242060
K7GWTrojan ( 0050ff861 )
K7AntiVirusTrojan ( 0050ff861 )
CyrenW32/S-5901d407!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Chzc-6960404-0
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusTrojan.Win32.Bladabindi.evcolf
RisingBackdoor.Bladabindi!8.B1F (TFE:C:UEYsBWW0fwR)
Ad-AwareGen:Variant.Zusy.242060
EmsisoftGen:Variant.Zusy.242060 (B)
ComodoTrojWare.MSIL.Fsysna.JNF@7ebfjl
F-SecureHeuristic.HEUR/AGEN.1135479
DrWebBackDoor.Bladabindi.13678
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FNCL!DCAF7AB1D8BB
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bbhou
AviraHEUR/AGEN.1135479
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanDownloader:MSIL/Lorozoad.A
ArcabitTrojan.Zusy.D3B18C
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataGen:Variant.Zusy.242060
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_MDA.R282220
Acronissuspicious
ALYacGen:Variant.Zusy.242060
MAXmalware (ai score=100)
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.JNF
TencentMsil.Trojan.Generic.Wurf
YandexTrojan.Agent!RNCHFxVU6ig
IkarusTrojan.MSIL.Krypt
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.JQG!tr
BitDefenderThetaGen:NN.ZemsilF.34804.fm0@a0zRhbk
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.1d8bb4
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.7c5

How to remove TrojanDownloader:MSIL/Lorozoad.A?

TrojanDownloader:MSIL/Lorozoad.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment