Trojan

About “Trojan:MSIL/Downloader.SHAZ!MTB” infection

Malware Removal

The Trojan:MSIL/Downloader.SHAZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Downloader.SHAZ!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Downloader.SHAZ!MTB?


File Info:

name: C089F1AB1F5296FAE8C7.mlw
path: /opt/CAPEv2/storage/binaries/80f2e975d37eaa0391a4191d0d2ad7f2ade5a4880458bd82514aed11df92707a
crc32: 71A9629A
md5: c089f1ab1f5296fae8c7820904c21b19
sha1: 888c5152977716382d8730e35372eae4327d9bae
sha256: 80f2e975d37eaa0391a4191d0d2ad7f2ade5a4880458bd82514aed11df92707a
sha512: febfd55509d90e119fac3a5948fa8a86b66f1251ccb646175629c55fe8a5827146c976e9d67bb9a52035d7ca279850d13480ec4d3447ff6493298b34521a036a
ssdeep: 12288:lq1NBnge630VAuAb2ii1mmP8zPqAe2o1VK:oBngedWsi4YbhoLK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151E47C1997F1CE04C27E37BAC559401623B96912D762EB2BDEC068E31EE13914E4BF4B
sha3_384: 1cc588e3e5ed9f4bd5961b3d52fe0c826dbfc2e34e1a0e3b8556b829d64bf173c74d9528613911d27104a6f1cd8c6174
ep_bytes: ff250020400001020304050607080000
timestamp: 2022-01-28 07:16:44

Version Info:

Translation: 0x0000 0x04b0
Comments: Razer Synapse 3
CompanyName: Razer Inc
FileDescription: Razer Synapse
FileVersion: 1.0.0.0
InternalName: OtelRezervasyonu.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: OtelRezervasyonu.exe
ProductName: OtelRezervasyonu
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/Downloader.SHAZ!MTB also known as:

LionicTrojan.MSIL.NetWiredRC.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.1174
MicroWorld-eScanTrojan.GenericKD.48248028
FireEyeTrojan.GenericKD.48248028
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKD.48248028
CylanceUnsafe
ZillyaDownloader.Agent.Win32.460975
SangforTrojan.MSIL.Agent.JWK
K7AntiVirusTrojan-Downloader ( 0058c49f1 )
K7GWTrojan-Downloader ( 0058c49f1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.PSWStealer.DFI
CyrenW32/MSIL_Troj.BXB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/TrojanDownloader.Agent.JWK
TrendMicro-HouseCallTrojan.MSIL.DLOADR.AUSYU
KasperskyHEUR:Backdoor.MSIL.NetWiredRC.gen
BitDefenderTrojan.GenericKD.48248028
AvastWin32:DropperX-gen [Drp]
Ad-AwareTrojan.GenericKD.48248028
SophosMal/Generic-R + Troj/Dwnld-XB
ComodoMalware@#2avoj70ifx4kg
TrendMicroTrojan.MSIL.DLOADR.AUSYU
McAfee-GW-EditionRDN/GenericV
EmsisoftTrojan.GenericKD.48248028 (B)
IkarusTrojan-Downloader.MSIL.Agent
GDataMSIL.Trojan.PSE.1HMG9PY
AviraTR/Dldr.Agent.wkhln
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.3522D2F
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
ViRobotTrojan.Win32.Z.Agent.668672.AEX
MicrosoftTrojan:MSIL/Downloader.SHAZ!MTB
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.Generic.C4941382
McAfeeRDN/GenericV
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.NetWiredRC
YandexTrojan.DL.Agent!0l318iiAtq0
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.JWK!tr.dldr
AVGWin32:DropperX-gen [Drp]
PandaTrj/WLT.G
MaxSecureTrojan.Malware.73979747.susgen

How to remove Trojan:MSIL/Downloader.SHAZ!MTB?

Trojan:MSIL/Downloader.SHAZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment