Trojan

Trojan:MSIL/Bingoml!mclg removal tips

Malware Removal

The Trojan:MSIL/Bingoml!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Bingoml!mclg virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/Bingoml!mclg?


File Info:

name: 5ADCBEC3A31E6FACECFA.mlw
path: /opt/CAPEv2/storage/binaries/66ec45ab3bb0b5c8c9f06eb30f71fb5446310dd81c2e8648dd07e878a390ca95
crc32: AA059F49
md5: 5adcbec3a31e6facecfad37773d8efff
sha1: 95c12bf9505f0a3ddbbba4014c3bc5f40096a6f4
sha256: 66ec45ab3bb0b5c8c9f06eb30f71fb5446310dd81c2e8648dd07e878a390ca95
sha512: dbe1075a869301b706b8faf38cc074117d94a86444e1c7830f859c6b625904c3af1d020eb192ff3ac0e7a17c52366cd3a01627d0d5850322388b31cd333ed5b4
ssdeep: 49152:LEunUVgQzeweKASR5s2PxD0lLC7R18tggrwB:LEunUVupdT2PV0RUqggcB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E75125732DC3CCAD13866B4773BA7C0E72EED465011CA8DB6CA1186AABE31771027D6
sha3_384: 972db2259753b7cac20b4973f7b342b882959c577fb5cb752fe5c3fb264d5e400af9fe3d59e0e88d79537ed697b15950
ep_bytes: ff250020400000000000000000000000
timestamp: 2086-03-31 17:40:44

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: OneCup ©
FileDescription: OneCup
FileVersion: 1.0.0.0
InternalName: loader.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: loader.exe
ProductName: OneCup
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/Bingoml!mclg also known as:

LionicTrojan.Win32.Lazy.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.5adcbec3a31e6fac
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeGenericRXMC-CY!5ADCBEC3A31E
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusUnwanted-Program ( 005234291 )
K7GWUnwanted-Program ( 005234291 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/DllInject.XU potentially unsafe
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Msilperseus-9824575-0
BitDefenderTrojan.GenericKD.38581491
MicroWorld-eScanTrojan.GenericKD.38581491
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKD.38581491
EmsisoftTrojan.GenericKD.38581491 (B)
ComodoApplicUnwnt@#1q195ah5kuetf
TrendMicroTROJ_GEN.R01FC0PAL22
McAfee-GW-EditionGenericRXMC-CY!5ADCBEC3A31E
SophosGeneric PUA JF (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38581491
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.350D635
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:MSIL/Bingoml!mclg
AhnLab-V3Malware/Win32.RL_Generic.C4301685
ALYacTrojan.GenericKD.38581491
MalwarebytesMalware.AI.3593055847
TrendMicro-HouseCallTROJ_GEN.R01FC0PAL22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:EXbLiW1w3YWwFpk6/qnotw)
YandexRiskware.Agent!qvqakq+67fM
FortinetAdware/DllInject
BitDefenderThetaGen:NN.ZemsilF.34232.Hn0@aWKm!yh
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.3a31e6
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:MSIL/Bingoml!mclg?

Trojan:MSIL/Bingoml!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment