Trojan

Should I remove “Trojan:MSIL/Autorun.J!ibt”?

Malware Removal

The Trojan:MSIL/Autorun.J!ibt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Autorun.J!ibt virus can do?

  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:MSIL/Autorun.J!ibt?


File Info:

name: B951F9F0BAD2735245AF.mlw
path: /opt/CAPEv2/storage/binaries/c2a93811c548441c64bfd0a9423551447191187bb77f85f95131050426278733
crc32: 0E803557
md5: b951f9f0bad2735245aff26b440811e6
sha1: 0b0f61158a6436530449d11cb8be07831fd39317
sha256: c2a93811c548441c64bfd0a9423551447191187bb77f85f95131050426278733
sha512: 7462c483a6c674204536739950518ff77e79f106dd9b022146b795fc98fb736fbbbe4d416042d460fae96f334715287e5e920f9e12fc3a352160f07db8c4c91d
ssdeep: 98304:IVWdPvz+L20LDDzbzIiRVNkBBmEKymAxn4fFUG/:tPJ0v/bV9PyrxnAaW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192F533815B953C49E89CC938D4BE8ABE12F305E43EF1D405219EB3142B77647E69EFA0
sha3_384: 4eb3fe4287a7f191d6ab8d3b769f9749ad0f5b5bc68a85ba35f586b1112bc089ca54a432226c9f5f668eb92905283217
ep_bytes: ff2500404000000000033001000f0000
timestamp: 2011-12-11 15:11:32

Version Info:

0: [No Data]

Trojan:MSIL/Autorun.J!ibt also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.20625
FireEyeGeneric.mg.b951f9f0bad27352
McAfeeGenericRXHH-HW!B951F9F0BAD2
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.139846
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005942951 )
BitDefenderIL:Trojan.MSILZilla.20625
K7GWTrojan ( 005942951 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZemsilF.34582.wtZ@a0VlBxEi
CyrenW32/Trojan.DND.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Autorun.Agent.LP
APEXMalicious
ClamAVWin.Malware.Msilzilla-9952725-0
KasperskyHEUR:Trojan-Ransom.Win32.Agent.gen
RisingRansom.Agent!8.6B7 (TFE:dGZlOg0ndEXA5cchUA)
Ad-AwareIL:Trojan.MSILZilla.20625
SophosML/PE-A + Troj/MSIL-SRG
DrWebWin32.HLLW.Autoruner2.49080
VIPREIL:Trojan.MSILZilla.20625
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.wc
EmsisoftIL:Trojan.MSILZilla.20625 (B)
IkarusWorm.MSIL.Autorun
JiangminTrojan.Agent.bwpe
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.C78
MicrosoftTrojan:MSIL/Autorun.J!ibt
GDataIL:Trojan.MSILZilla.20625
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R264006
VBA32TScope.Trojan.MSIL
ALYacIL:Trojan.MSILZilla.20625
MalwarebytesMalware.AI.4266414405
TencentTrojan.Msil.Agent.zav
YandexWorm.Autorun!ltoLbalhqn8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.LP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.0bad27
AvastWin32:Malware-gen

How to remove Trojan:MSIL/Autorun.J!ibt?

Trojan:MSIL/Autorun.J!ibt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment