Malware

MSIL/Disabler.DR removal

Malware Removal

The MSIL/Disabler.DR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Disabler.DR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MSIL/Disabler.DR?


File Info:

name: 19B9BB1AF6815AC1023E.mlw
path: /opt/CAPEv2/storage/binaries/5d05787966554439bfd1e402fcd1228079075ec76229b3f071f5db2dfd4c8434
crc32: 1A8D095B
md5: 19b9bb1af6815ac1023ec789f24efd69
sha1: 02cdf243d0a6f26a1b63e1819ab67acded94d1b1
sha256: 5d05787966554439bfd1e402fcd1228079075ec76229b3f071f5db2dfd4c8434
sha512: c51d684ddca9a342d00c602f43be3100d6ecb0fa08d52ecaa9d848325c76476946f2a98c5922a56f607ef74c3c7d2ba17260af86a2fd055b9b9f49439f2047df
ssdeep: 12288:3Mr6y90yAcbLZSFVDythdCmpvzuHk7RPnaXrL4NO1HJxqBd662s:xy3Acb+yth5r37M7hHjqBQ6z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FE41207A7ED9422E4B0677048F602D30A3ABD918F38939B664F5D1E1C7317166363BB
sha3_384: bf3aa56001c193fa497c076af1218b0206e5ed76904e7182eb0963398bf3ff9f162c7036163362e1aa55735add2fa667
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

MSIL/Disabler.DR also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen19.32857
FireEyeGeneric.mg.19b9bb1af6815ac1
CAT-QuickHealTrojan.MSIL
ALYacTrojan.GenericKD.65331035
MalwarebytesGeneric.Trojan.Injector.DDS
K7AntiVirusTrojan ( 005690671 )
K7GWTrojan ( 005690671 )
Cybereasonmalicious.af6815
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Disabler.DR
APEXMalicious
ClamAVWin.Packed.Disabler-9987080-0
KasperskyUDS:Trojan.Win32.Zenpak.gen
NANO-AntivirusTrojan.Win32.Disabler.junsud
TencentTrojan-Ransom.Win32.Stop.gen
BaiduMulti.Threats.InArchive
VIPRETrojan.GenericKD.65331035
TrendMicroTROJ_GEN.R002C0PBK23
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious SFX
GoogleDetected
AviraTR/Disabler.ocayi
Antiy-AVLTrojan/Script.Phonzy
XcitiumApplicUnwnt@#1ftfc2ja2g1dd
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataGeneric.Trojan.PSEB.WGPCII
CynetMalicious (score: 99)
McAfeeArtemis!F3485715FE2D
TrendMicro-HouseCallTROJ_GEN.R002C0PBK23
RisingTrojan.Generic@AI.100 (RDML:xWzKJ8nRNRBOA1miYwlqPw)
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan.Win32.Crypt
FortinetPossibleThreat
CrowdStrikewin/malicious_confidence_90% (D)

How to remove MSIL/Disabler.DR?

MSIL/Disabler.DR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment