Trojan

Trojan:MSIL/SuspMsilInArcEmail.AA malicious file

Malware Removal

The Trojan:MSIL/SuspMsilInArcEmail.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/SuspMsilInArcEmail.AA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan:MSIL/SuspMsilInArcEmail.AA?


File Info:

name: 5ABA5AFABF7734033689.mlw
path: /opt/CAPEv2/storage/binaries/5748055ad71d7d3807e7a58719cf8c8efc0320cf223ec02fee77b7adbec3cf69
crc32: 1F1DE03B
md5: 5aba5afabf773403368929ecb2c23199
sha1: e79e809c114d89dad48399edb127927fd2975b8c
sha256: 5748055ad71d7d3807e7a58719cf8c8efc0320cf223ec02fee77b7adbec3cf69
sha512: 8469efa6c8ad3b802b1b3ecbc0e24f2baafa3c6d4be3223e2f335ae639e58a0eb517120d18d8a03d870486f2a9b24aa57a93d20f424c5823e148f77e233476bb
ssdeep: 12288:f3DkEGDINi1EwkG8Fs+Yr33gjizwBKQaAZnpjlfZoiXge+O2aXvtj/BwVrsHWihL:/DkUNi1EvGn+5izsKoZpjlfMelj/aaWa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4051221BAD18471E4B228351EE1B331AB7DB9700B368FDF5B444A1D5F309C16A35BAB
sha3_384: 234cf36440215ad6befb7d98a6f0705826606cbb9fcf46cf9f51ea799bbba3e9619c1ffd1b6b86bbde3f69c94d15189d
ep_bytes: e8dc040000e978feffffe98a46000055
timestamp: 2023-05-29 16:03:38

Version Info:

0: [No Data]

Trojan:MSIL/SuspMsilInArcEmail.AA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zenpak.tspc
CynetMalicious (score: 100)
FireEyeGeneric.mg.5aba5afabf773403
McAfeeArtemis!5ABA5AFABF77
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1726339
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Taskun.0acd0e19
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c114d8
VirITTrojan.Win32.MSIL_Heur.A
CyrenW32/Agen.GHVH-6183
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.GMWG
APEXMalicious
KasperskyTrojan.Win32.Taskun.bq
BitDefenderTrojan.Generic.34093161
MicroWorld-eScanTrojan.Generic.34093161
AvastWin32:PWSX-gen [Trj]
SophosMal/Generic-R
F-SecureBackdoor.BDS/NanoBot.haljw
DrWebTrojan.DownLoaderNET.710
VIPRETrojan.Generic.34093161
TrendMicroTROJ_GEN.R002C0DHH23
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftTrojan.Generic.34093161 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Generic.34093161
WebrootW32.Trojan.Gen
AviraBDS/NanoBot.haljw
ZoneAlarmTrojan.Win32.Taskun.bq
MicrosoftTrojan:MSIL/SuspMsilInArcEmail.AA
Acronissuspicious
VBA32TrojanSpy.Cordimik
ALYacTrojan.Generic.34093161
MAXmalware (ai score=85)
MalwarebytesGeneric.Crypt.Trojan.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DHH23
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Igent.b0GqgN.4
IkarusTrojan.MSIL.Inject
FortinetMSIL/Kryptik.ATU!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/SuspMsilInArcEmail.AA?

Trojan:MSIL/SuspMsilInArcEmail.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment