Trojan

Trojan:MSIL/Otcontavir.A malicious file

Malware Removal

The Trojan:MSIL/Otcontavir.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Otcontavir.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/Otcontavir.A?


File Info:

name: B4FDFA355BC0A38A7D61.mlw
path: /opt/CAPEv2/storage/binaries/fd735cf9cc339da5baccd3660dc755c0250889d81d5e0aba00b98cfccafcd4f1
crc32: A6324219
md5: b4fdfa355bc0a38a7d610df48a163eca
sha1: c6217665f21b7c902dfc38032a74a6e833ddf705
sha256: fd735cf9cc339da5baccd3660dc755c0250889d81d5e0aba00b98cfccafcd4f1
sha512: 97a02325c264f3907d53d066af3552b863569bc2056fc3cf04928b8ccbeb94552dff49d3877efe94af74eccd786fdd8c964c69ccba80894babd7e11a09ea72e2
ssdeep: 98304:BFbVfjQO5NMUPg4mVQCvJo4LeuvdW8xkjJtfhpEG4Hx1YYr4SWpau3udzXKtXLvP:/SO5NMmoSqPeuFW8u1dhWG4zB9St320D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C3633353B98D0BAC17325316DF686797E68FC712B725C8D6F910EAE2F758228106B43
sha3_384: 6a574ee5fdf874cac5f1f027717a82cb4e699f5a779c5823402d4263494cc5dcc4ef6811e5a81e28812db19e9e43fb42
ep_bytes: e885630000e978feffff8bff558bec56
timestamp: 2015-02-15 08:00:31

Version Info:

0: [No Data]

Trojan:MSIL/Otcontavir.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.Agent.f!c
MicroWorld-eScanTrojan.ScriptKD.2641
FireEyeTrojan.ScriptKD.2641
ALYacGen:Variant.Zusy.190647
CylanceUnsafe
SangforTrojan.MSIL.Otcontavir.A
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:MSIL/Otcontavir.1a1c1bdd
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen
ESET-NOD32a variant of Generik.FYRBHIP
APEXMalicious
KasperskyTrojan-Mailfinder.MSIL.Agent.b
BitDefenderTrojan.ScriptKD.2641
NANO-AntivirusTrojan.Win32.GTUH7338.ecpjjm
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generik.Phqj
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJM21
McAfee-GW-EditionBehavesLike.Win32.Coinminer.tc
EmsisoftTrojan.ScriptKD.2641 (B)
WebrootW32.Trojan.Scriptkd
AviraJS/Agent.dbxu
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Otcontavir.A
GDataGen:Variant.Zusy.190647
CynetMalicious (score: 99)
McAfeeArtemis!B4FDFA355BC0
MAXmalware (ai score=82)
MalwarebytesMalware.AI.4177914909
IkarusTrojan.VBS.Crypt
FortinetW32/Agent.B!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.55bc0a
PandaTrj/CI.A
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Trojan:MSIL/Otcontavir.A?

Trojan:MSIL/Otcontavir.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment