Trojan

TrojanDropper:Win32/VB.IL removal guide

Malware Removal

The TrojanDropper:Win32/VB.IL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/VB.IL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to disable or modify Explorer Folder Options
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine TrojanDropper:Win32/VB.IL?


File Info:

name: 47408E6AA593A07B7FAD.mlw
path: /opt/CAPEv2/storage/binaries/141bce2f6ebbc53a27800d8d65b54e2275b6b925e94c9d4b6fd4de2f50cabfab
crc32: 2FC94ED8
md5: 47408e6aa593a07b7fad082bcfec8bde
sha1: fb612e1f622d9ed31627a69fbb675084db29bc7a
sha256: 141bce2f6ebbc53a27800d8d65b54e2275b6b925e94c9d4b6fd4de2f50cabfab
sha512: b03bdf37f4c696ac7ac7616f260c1b8d9b87495f3df44969be1285c85d3ee20e8c2c5f4ef0bfb1a45d65dfbed0e8090007b5a48ea3156edf6494535cb74f067f
ssdeep: 768:CpQNwC3BESe4Vqth+0V5vKPyLylze70wi3BEma:CeT7BVwxfvLFwjRa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7A402D8C555BE39C78729BAD024EE0A10362CE0F366C4B7F87B72C1FAB55C23564929
sha3_384: 6737860706f158676c32766ce9697b8a3006b436cc79ea41c024ceeee3f7272c25fa77667c6694af0433fdbfe211ed2f
ep_bytes: 68946d4000e8f0ffffff000000000000
timestamp: 2009-01-06 04:02:14

Version Info:

Translation: 0x0409 0x04b0
CompanyName: SBC
ProductName: Microsoft Windows
FileVersion: 1.00.0057
ProductVersion: 1.00.0057
InternalName: musicvn
OriginalFilename: musicvn.exe

TrojanDropper:Win32/VB.IL also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.Generic.4385790
ClamAVWin.Malware.Genpack-6989317-0
FireEyeGeneric.mg.47408e6aa593a07b
ALYacTrojan.Generic.4385790
CylanceUnsafe
ZillyaTrojan.Vilsel.Win32.13108
SangforWorm.Win32.VB.pro3
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.aa593a
BaiduWin32.Trojan.VB.x
CyrenW32/Vilsel.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.OZA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vilsel.loy
BitDefenderTrojan.Generic.4385790
NANO-AntivirusTrojan.Win32.Vilsel.fwrjnb
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Vilsel-CT [Trj]
TencentTrojan.Win32.VB.ctb
Ad-AwareTrojan.Generic.4385790
EmsisoftTrojan.Generic.4385790 (B)
ComodoTrojWare.Win32.Trojan.Vilsel.loy0@1qq4nk
DrWebTrojan.Copyself.102
VIPRETrojan.Generic.4385790
TrendMicroTROJ_GEN.R03BC0DHS22
McAfee-GW-EditionBehavesLike.Win32.Generic.gt
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/VB-F
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Vilsel.A
JiangminTrojan/Vilsel.adtk
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.76
ArcabitTrojan.Generic.D42EBFE
ZoneAlarmTrojan-Ransom.Win32.Blocker.kjac
MicrosoftTrojanDropper:Win32/VB.IL
GoogleDetected
AhnLab-V3Win-Trojan/VBKrypt.RP04.X1877
Acronissuspicious
McAfeeGeneric VB.z
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_GEN.R03BC0DHS22
RisingTrojan.VB!1.BAD4 (CLASSIC)
YandexTrojan.Vilsel!QlcS5IdPwZo
IkarusTrojan.Win32.Scar
MaxSecureTrojan.W32.Vilsel.loy
BitDefenderThetaAI:Packer.0B6DD7F41C
AVGWin32:Vilsel-CT [Trj]
PandaTrj/Vilsel.V
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDropper:Win32/VB.IL?

TrojanDropper:Win32/VB.IL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment