Threat Database Trojans Trojan.MSILZilla

Trojan.MSILZilla

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 39
First Seen: May 22, 2022
Last Seen: January 11, 2026
OS(es) Affected: Windows

The detection of Trojan.MSILZilla on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system. It's crucial to approach this situation with a clear understanding of the risks and the necessary actions to mitigate them.

What Is Trojan.MSILZilla?

Trojan.MSILZilla is identified as a Trojan-type threat, which means it is a type of malware that disguises itself as a legitimate software program but actually allows unauthorized access to the victim's system. Trojans can lead to a variety of malicious activities, including data theft, spyware installation, and exploitation of system vulnerabilities. The name itself does not directly link to a known malware family, suggesting it could be a variant or a newly discovered threat.

How Trojan.MSILZilla Operates

Trojan.MSILZilla, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means such as downloading infected software, opening malicious email attachments, or clicking on compromised links. Once installed, it can create backdoors for remote access, allowing attackers to control the infected system, steal sensitive information, or use the system for malicious activities like spamming or distributing malware.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include unusual system behavior such as slowed performance, frequent crashes, or unfamiliar programs and icons appearing on the desktop. Users might also notice changes in their browser settings, unexpected pop-ups, or redirected web searches. In some cases, the infection might not display obvious symptoms, making it difficult for users to detect without running a thorough system scan.

How to Remove Trojan.MSILZilla

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode. This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Run a Full Scan with a Reputable Tool: Use an anti-malware tool like SpyHunter to perform a full scan of your system. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the Trojan.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you do not recognize or that were installed around the time the symptoms started.
  4. Reset Your Browser: Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot and Re-scan: After taking the above steps, reboot your computer and run another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSILZilla requires careful and immediate action to prevent further damage to your system and protect your personal data. By following the steps outlined in this report, you should be able to remove the threat. However, prevention is key; always be cautious when downloading software, avoid suspicious links and attachments, and keep your antivirus and operating system updated. Regular system scans and backups can also help in early detection and recovery from such threats. Remember, staying informed and vigilant is your best defense against malware and other cyber threats.

Analysis Report

General information

Family Name: Trojan.MSILZilla
Signature status: No Signature

Known Samples

MD5: 614ea3a29cb2688760c7517c1ec0bdca
SHA1: b5ec5c741eb33328eff868e86ddb7adcdcc6a006
SHA256: C55B58E05AA419DBF3786D6522AC260594141A1F54CED97F6B5A6C48C8D9A864
File Size: 122.88 KB, 122880 bytes
MD5: aa98ce357dae9a8fea9d1ea301a2a510
SHA1: 9280b6d646da4fefb5ac8f48c9c3a08fe33a9117
SHA256: FB9B15B7A19F15DA480190040F9C71FF32FD2400B8474FC9C0C4FCBCABC8CECF
File Size: 131.58 KB, 131584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • Dead Fish
  • PacketTracerPatcher
File Version 1.0.0.0
Internal Name
  • Dead Fish.exe
  • PacketTracerPatcher.exe
Legal Copyright
  • Copyright © 2019
  • Copyright © 2022
Original Filename
  • Dead Fish.exe
  • PacketTracerPatcher.exe
Product Name
  • Dead Fish
  • PacketTracerPatcher
Product Version 1.0.0.0

File Traits

  • .NET
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 30
Potentially Malicious Blocks: 25
Whitelisted Blocks: 5
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x 0 0 0 0 0 x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • KillMBR.W
  • KillMBR.WA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...