Malware

About “MSIL/Disabler.DR” infection

Malware Removal

The MSIL/Disabler.DR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Disabler.DR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MSIL/Disabler.DR?


File Info:

name: C60A080F557D421B5BEC.mlw
path: /opt/CAPEv2/storage/binaries/b8744a9fa005aebbc9c3402014ed1cef9454bc603e793d710f04a265e0ad9739
crc32: 734C299E
md5: c60a080f557d421b5bec7e9e58c0c25c
sha1: e804c30c9f068baec0a1fa4ad6f550dcaddbad39
sha256: b8744a9fa005aebbc9c3402014ed1cef9454bc603e793d710f04a265e0ad9739
sha512: 59851a7fbfad2888e2f21804079445422a091792e4eeff64c7c5fe6aef906c4ef30ece0d81f0fc7b8f4542e4eab44110f4b71690bce99e7a93d3a6460d985226
ssdeep: 6144:KZy+bnr+Bp0yN90QE/Gayzdq9+slMoebwSdLdQsJM9i7yT48gAaZ:zMrpy90oah98lt/Qs6zc5Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19574F107EBFC8132F8B453B018F702C30A35BE616B38839A674E6D5E1DB15A1653676B
sha3_384: 14c67d2bc05b6452e4c83d6e8cee75a7466b917944be51305c248f69b9c24ea4f9a7cec91037e00e7a04e3c2ebb3afe3
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

MSIL/Disabler.DR also known as:

DrWebTrojan.Siggen19.32857
ClamAVWin.Packed.Disabler-9987080-0
FireEyeGeneric.mg.c60a080f557d421b
CAT-QuickHealTrojan.MSIL
ALYacTrojan.GenericKD.65331035
K7AntiVirusTrojan ( 00516fdf1 )
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.f557d4
VirITTrojan.Win32.MSIL.EY
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Disabler.DR
APEXMalicious
CynetMalicious (score: 99)
KasperskyVHO:Trojan.Win32.Convagent.gen
NANO-AntivirusTrojan.Win32.Disabler.juzdmw
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.hg
VIPRETrojan.GenericKD.65331035
TrendMicroRansom.Win32.STOP.SMYXDBTB.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Suspicious SFX
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Script.Phonzy
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Script/Phonzy.A!ml
GoogleDetected
AhnLab-V3Trojan/Win.SmokeLoader.C5390844
McAfeePWS-FDON!4596E078E86E
MalwarebytesTrojan.Crypt.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PBQ23
RisingTrojan.Disabler!8.B58 (CLOUD)
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan-Banker.UrSnif
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MSIL/Disabler.DR?

MSIL/Disabler.DR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment