Trojan

TrojanDropper:MSIL/Dicsor malicious file

Malware Removal

The TrojanDropper:MSIL/Dicsor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:MSIL/Dicsor virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine TrojanDropper:MSIL/Dicsor?


File Info:

name: 1423B537E7CADA979D6B.mlw
path: /opt/CAPEv2/storage/binaries/3e388db959b4b7467a62b4289afb83c5c6a632736757cf1fec33bd12c4d30724
crc32: DB6E5FCF
md5: 1423b537e7cada979d6b9b24178bf894
sha1: cd722f556a2401be19e1fee969a60ebf3bd04fad
sha256: 3e388db959b4b7467a62b4289afb83c5c6a632736757cf1fec33bd12c4d30724
sha512: 3281e2e81e2f4c8b6eef5b65d461b4d3e1f47c4c39846ca63441dac4cf39c5b7028660959170436a6b74248f04d8eccddcca2a4e092a586e0c2d9e01e2337e28
ssdeep: 24576:J70HDFv6SIWMkWy7k6frZgfk/PVCGTMiPaL53wwMy8LEZdDom:p4DFv9pR/PkbiPaxS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D6523210F5C8FDEC9090339149F2E0DB9F65F16515EADCDA8A09C43A7EEEE4452E8B4
sha3_384: adcfbe9b192a262e1f9d2242fcdda29801a2eb290a41178f4fcd4945e8c7f5ccc21a3690b61acc1714acfde4778b839b
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-21 23:02:56

Version Info:

Translation: 0x0000 0x04b0
Comments: Description
CompanyName: Company
FileDescription: Title
FileVersion: 1.0.0.0
InternalName: joo.exe
LegalCopyright: Copyright
LegalTrademarks: Trademark
OriginalFilename: joo.exe
ProductName: Product
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

TrojanDropper:MSIL/Dicsor also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 100)
McAfeeTrojan-FBXE!1423B537E7CA
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 00593af91 )
K7GWSpyware ( 00593af91 )
Cybereasonmalicious.7e7cad
CyrenW32/S-463f3c46!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.XC
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderTrojan.MSIL.Basic.3.Gen
NANO-AntivirusTrojan.Win32.SCKeyLog.dhxrqz
MicroWorld-eScanTrojan.MSIL.Basic.3.Gen
AvastWin32:Injector-AQK [Trj]
Ad-AwareTrojan.MSIL.Basic.3.Gen
EmsisoftTrojan.MSIL.Basic.3.Gen (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
McAfee-GW-EditionTrojan-FBXE!1423B537E7CA
FireEyeGeneric.mg.1423b537e7cada97
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.bxpn
AviraTR/Dropper.MSIL.Gen
MicrosoftTrojanDropper:MSIL/Dicsor.gen
ArcabitTrojan.MSIL.Basic.3.Gen
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataTrojan.MSIL.Basic.3.Gen
AhnLab-V3Trojan/Win.Generic.C4580051
Acronissuspicious
ALYacTrojan.MSIL.Basic.3.Gen
MAXmalware (ai score=86)
MalwarebytesTrojan.Injector.MSIL.Generic
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:eu6lFOIQvGCNLqdaseX3eQ)
IkarusVirus.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.XC!tr
BitDefenderThetaGen:NN.ZemsilF.34742.En0@aiu7Usm
AVGWin32:Injector-AQK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:MSIL/Dicsor?

TrojanDropper:MSIL/Dicsor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment