Trojan

About “Trojan:MSIL/Wizrem.IOF!MTB” infection

Malware Removal

The Trojan:MSIL/Wizrem.IOF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Wizrem.IOF!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/Wizrem.IOF!MTB?


File Info:

crc32: AD0C2C78
md5: c75a067daf074e37c2bd6b3a38f73a8e
name: C75A067DAF074E37C2BD6B3A38F73A8E.mlw
sha1: 0e14e19ae4d413650f6bbc83a95c8d514c3b8c31
sha256: 159455ee2d2fefac98bc35c9d0463a5ffeda2a1011283f59afa3a15b13a20e36
sha512: 4e97bd67394d6c4dfa2b7c1f9e37b3dd3cf07a40465e82855aaaf6fe91253fa5dfc95089c083e75fd2e62651de0679d4a0f08c6a2e4e60457667c215d65c9d84
ssdeep: 12288:ZzpgilrOYbEH/5IJ+z75PydsAdrHe0p1XjuQhaXcucCJ2FsVrpCe+v1t:9nO2ERIkwjlhyrRQUrx+9t
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 4912
Assembly Version: 2.1.7.7
InternalName: INDETERMINEE.exe
FileVersion: 0.2.6.8
CompanyName: YPY
LegalTrademarks:
Comments: YPYM
ProductName: YPYM6OGD
ProductVersion: 0.2.6.8
FileDescription: YPYM6O
OriginalFilename: INDETERMINEE.exe

Trojan:MSIL/Wizrem.IOF!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.Injector.LU
FireEyeGeneric.mg.c75a067daf074e37
ALYacTrojan.MSIL.Injector.LU
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0051b9181 )
BitDefenderTrojan.MSIL.Injector.LU
K7GWTrojan ( 0051b9181 )
Cybereasonmalicious.daf074
CyrenW32/S-64c97e90!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Wizrem.36df149b
NANO-AntivirusTrojan.Win32.Kryptik.ewchle
ViRobotTrojan.Win32.Z.Injector.845824.AG
TencentWin32.Trojan.Generic.Sxxy
Ad-AwareTrojan.MSIL.Injector.LU
SophosMal/Kryptik-AL
ComodoTrojWare.MSIL.Injector.QTZ@6mgpxg
F-SecureAdware.ADWARE/Wizrem.Gen7
DrWebAdware.Eorezo.958
ZillyaTrojan.Kryptik.Win32.1120209
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftTrojan.MSIL.Injector.LU (B)
SentinelOneStatic AI – Malicious PE
AviraADWARE/Wizrem.Gen7
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Wizrem.IOF!MTB
ArcabitTrojan.MSIL.Injector.LU
SUPERAntiSpywareAdware.Tuto4PC/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.MSIL.Injector.LU
CynetMalicious (score: 90)
AhnLab-V3PUP/Win32.Bundler.R198400
Acronissuspicious
McAfeeGenericRXBD-SI!C75A067DAF07
MAXmalware (ai score=87)
MalwarebytesAdware.Tuto4PC
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.IOF
TrendMicro-HouseCallTROJ_GEN.R002C0DB121
RisingTrojan.Dynamer!8.3A0 (TFE:C:l0otT9locRB)
YandexTrojan.Injector!icyW1dTHhT0
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.IOF!tr
BitDefenderThetaGen:NN.ZemsilF.34804.Zm0@ael3u8o
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.AD14.Malware.Gen

How to remove Trojan:MSIL/Wizrem.IOF!MTB?

Trojan:MSIL/Wizrem.IOF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment