Trojan

How to remove “Trojan:MSIL/Runner”?

Malware Removal

The Trojan:MSIL/Runner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Runner virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/Runner?


File Info:

crc32: CB97809C
md5: 222d7fde37ae344824a97087d473cdcd
name: 222D7FDE37AE344824A97087D473CDCD.mlw
sha1: 90205a2761ed7ac3b188230786ec2bebd30effba
sha256: 5d65ebdde1aef8f23114f95454287e7410965288f144d880ece2a2b8c3128645
sha512: 177f25c2e454b5366719a5536e25dbf16ab5cb01b1886b18ea1477671651191cbf663cf1754990c618be1d7c36bf523aaac8528d94a1d49583213dc8a0dee98a
ssdeep: 24576:PLvqxk7+y/4NmWPWKrbE6qqE56Hglx8zudJhTyGwcKe:+
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: obturator groundnut segner nonsensitization underfringe joint kiloampere lousy
Assembly Version: 13.16.18.19
InternalName: prelecturedexe.exe
FileVersion: 23.25.47.59
CompanyName: Theatregoer undemonstrational indianize atroceruleous resolute biochemic
LegalTrademarks: liquefaction fluoridated negationist tacitus bud. Dunsinane acidophilus
Comments: chigwell preinvasive aboral taxableness charlottetown semigod unelbowed nautch
ProductName: venetian norse unweighted epexegetical icbm perfervour pitchlike diseased
ProductVersion: 23.25.47.59
FileDescription: Supersympathetic elegit epopoeia contrariness encirclement collaborationism
OriginalFilename: prelecturedexe.exe

Trojan:MSIL/Runner also known as:

K7AntiVirusTrojan ( 0053adaa1 )
LionicTrojan.MSIL.Agent.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Samas.21
CylanceUnsafe
ZillyaTrojan.Runner.Win32.876
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Runner.e2ed2515
K7GWTrojan ( 0053adaa1 )
Cybereasonmalicious.e37ae3
CyrenW32/SamSam.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Runner.N
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.MSIL.Agent.fqpc
BitDefenderGen:Variant.Ransom.Samas.21
NANO-AntivirusTrojan.Win32.Ransom.fkxsro
MicroWorld-eScanGen:Variant.Ransom.Samas.21
TencentMsil.Trojan.Agent.Hnld
Ad-AwareGen:Variant.Ransom.Samas.21
SophosMal/Generic-R + Mal/Kryptik-BV
ComodoMalware@#3icyvjy7h3eko
F-SecureTrojan.TR/Ransom.Gen
BitDefenderThetaGen:NN.ZemsilF.34050.!m0@ayV9DAo
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SAMAS.JLHIO
McAfee-GW-EditionGenericRXGO-BB!222D7FDE37AE
FireEyeGeneric.mg.222d7fde37ae3448
EmsisoftGen:Variant.Ransom.Samas.21 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Ransomware.Samsam
AviraTR/Ransom.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2821179
MicrosoftTrojan:MSIL/Runner
ArcabitTrojan.Ransom.Samas.21
GDataGen:Variant.Ransom.Samas.21
AhnLab-V3Trojan/Win32.MSILKrypt.C2738527
McAfeeGenericRXGO-BB!222D7FDE37AE
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.SAMAS.JLHIO
YandexTrojan.Runner!Vvu5XucFuEM
IkarusTrojan-Ransom.SamSam
MaxSecureTrojan.Malware.74548125.susgen
FortinetW32/Runner.N!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Runner.HgIASOYA

How to remove Trojan:MSIL/Runner?

Trojan:MSIL/Runner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment