Trojan

Trojan:MSIL/Confuser information

Malware Removal

The Trojan:MSIL/Confuser is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Confuser virus can do?

  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Confuser?


File Info:

name: A37CB8A18432E4ECF250.mlw
path: /opt/CAPEv2/storage/binaries/1160b12c8a4ced39cfb94cd531200d459e4ff8b8a455f661e7f1397318a9e202
crc32: 2A978055
md5: a37cb8a18432e4ecf25018edfa6543a9
sha1: cec8616ea461a5859fbaa0af7e4a7b0d746c3728
sha256: 1160b12c8a4ced39cfb94cd531200d459e4ff8b8a455f661e7f1397318a9e202
sha512: f82d01d04552a42e36b1b2349a3f87a3a37f17224a5dd4c88ea5f5990d10682f49505bd8f5ae6a341d70679d395ecfeadef147974450c61d89fd59716508f5f8
ssdeep: 6144:52BC+MfXkjrb1wp1IwXUCXhP0YC8sYIUuZpzhCt8i5b45Tllca0BRhpiwr:52QXKrxwp1IXchPnQYIUEpzhU45h+ziw
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T182542346AEA5D13BCAFBA33D0D73C46819E593637821EF2AF106738176E9B812019347
sha3_384: 711270ce645256c6f59fe7054f8d187f7f10b157f2c628372a79b6cdc2eaf64c776040a92b5da683b82192994345f5b9
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-10-18 17:59:50

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Coleta
FileVersion: 2.1.0.0
InternalName: PSRunner_4.exe
LegalCopyright: Copyright © 2016
OriginalFilename: PSRunner_4.exe
ProductVersion: 2.1.0.0
Assembly Version: 2.1.0.0

Trojan:MSIL/Confuser also known as:

BkavW32.Common.569C6F1B
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.66496275
FireEyeGeneric.mg.a37cb8a18432e4ec
Cylanceunsafe
VIPRETrojan.GenericKD.66496275
SangforSuspicious.Win32.Save.a
AlibabaTrojanDropper:Win32/Generic.bc164195
Cybereasonmalicious.ea461a
VirITTrojan.Win32.MSIL_Heur.A
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.66496275
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.66496275 (B)
F-SecureTrojan.TR/Dropper.Gen
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Dropper
GDataTrojan.GenericKD.66496275
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Generic.D3F6A713
ViRobotTrojan.Win.Z.Dropper.302080
MicrosoftTrojan:MSIL/Confuser
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.C4246338
BitDefenderThetaGen:NN.ZemsilF.36662.sm0@aiYEYeo
ALYacTrojan.GenericKD.66496275
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1266601823
TrendMicro-HouseCallTROJ_GEN.R002H0CDK23
RisingMalware.Obfus/MSIL@AI.98 (RDM.MSIL2:0/kVFje6yAu2VBjstCfWGA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.209463516.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Confuser?

Trojan:MSIL/Confuser removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment