Trojan

TrojanDropper:MSIL/Livate.B malicious file

Malware Removal

The TrojanDropper:MSIL/Livate.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:MSIL/Livate.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine TrojanDropper:MSIL/Livate.B?


File Info:

name: E06CE6599EEC58DED8F1.mlw
path: /opt/CAPEv2/storage/binaries/1f5ad26014430615f8644cd75d5bcdae55ab7bf10845bf131ecf5dc10c0edbec
crc32: A4103130
md5: e06ce6599eec58ded8f15d2fa3d2281c
sha1: 27d973e14e4dd7deafdae46ccd71fa4619b6e08c
sha256: 1f5ad26014430615f8644cd75d5bcdae55ab7bf10845bf131ecf5dc10c0edbec
sha512: 6d139513a0282346aae3ffdce201980cb7c2b00892f60d45cb3e496fbc0972c83edb17103db77183caba1da985bd82cd7637a038a5709af8311b863202d83692
ssdeep: 49152:1xX7MjQcbfaxAfuEZlXb1OT4mG6UjwnMw6x0jRu7MGCAMCqgd5Hw5UUeGNUU:11Mraixb1lmG6UjwMwiQRuwBCVHIUpGy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8C5E122B2D18437D07307789D6B62A89429BF352E28AC4F7BE81D4D2F757913C29397
sha3_384: 8d58dfc8c0f6a114811d4dbeac30e0dd7d523d990c6d99fe18b3d42617595751d168b670530068bed1ef96d4a148cf1c
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-12-21 22:10:24

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Company
FileDescription: Product
FileVersion: 1.0.0.0
InternalName: SoftwareWrapper.exe
LegalCopyright: Copyright © Company 2011
OriginalFilename: SoftwareWrapper.exe
ProductName: Product
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

TrojanDropper:MSIL/Livate.B also known as:

LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.MSILPerseus.23212
FireEyeGeneric.mg.e06ce6599eec58de
SkyhighArtemis!PUP
McAfeeArtemis!E06CE6599EEC
MalwarebytesAdware.BHO
ZillyaAdware.Agent.Win32.83166
AlibabaAdWare:MSIL/BrowseFox.d15502bc
ESET-NOD32a variant of MSIL/Adware.BHO.D
BitDefenderGen:Variant.Application.MSILPerseus.23212
NANO-AntivirusTrojan.Win32.Drop.dcmkru
ViRobotAdware.Muldrop4.2712064
AvastWin32:GenMaliciousA-FOR [Adw]
EmsisoftGen:Variant.Application.MSILPerseus.23212 (B)
F-SecureAdware.ADSPY/Marklou.A
DrWebTrojan.MulDrop4.12709
VIPREGen:Variant.Application.MSILPerseus.23212
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.Vicenor
WebrootW32.Gen.BT
GoogleDetected
AviraADSPY/Marklou.A
Antiy-AVLGrayWare[AdWare]/MSIL.BHO
Kingsoftmalware.kb.c.998
MicrosoftTrojanDropper:MSIL/Livate.B
XcitiumMalware@#3f5u4k0lx809e
ArcabitTrojan.Application.MSILPerseus.D5AAC
GDataGen:Variant.Application.MSILPerseus.23212
ALYacGen:Variant.Application.MSILPerseus.23212
MAXmalware (ai score=83)
VBA32TScope.Trojan.Delf
Cylanceunsafe
RisingDropper.Livate!8.D59 (CLOUD)
YandexPUA.BHO!LegBCjTrfw4
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Agent
AVGWin32:GenMaliciousA-FOR [Adw]
Cybereasonmalicious.99eec5
DeepInstinctMALICIOUS
alibabacloudAdWare:MSIL/Bho.D

How to remove TrojanDropper:MSIL/Livate.B?

TrojanDropper:MSIL/Livate.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment