Malware

MSIL/Injector.BZH (file analysis)

Malware Removal

The MSIL/Injector.BZH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.BZH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine MSIL/Injector.BZH?


File Info:

crc32: 51C5FD40
md5: 50076387a35da333c7c571421da374f7
name: 50076387A35DA333C7C571421DA374F7.mlw
sha1: f2705a6c14524bca1d79046218d54c11e55e466d
sha256: 23aa7ba44ff6178a8fec6d063f57b98d6136c3e39d201bec8da3b305fd64211f
sha512: 107f9be707b9f1dc65b99b2d35b41d0eddc96909be79ce218c6521e04fe3d6ef252fb7f785897c989c47bddd532145b657ce34cab59a668134df8e9639545679
ssdeep: 3072:wYYYYYuVZGUmCtb/FfMTaTTa5UMUFfwyG4VOS6YflI2neg:wYYYYYuVZGmtWcaxUWmb6Yflhn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Injector.BZH also known as:

K7AntiVirusTrojan ( 004b92ff1 )
LionicTrojan.Win32.Generic.m8Tv
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.23317
CynetMalicious (score: 100)
ALYacGen:Variant.MSIL.Lynx.55
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/Injector.93e0f646
K7GWTrojan ( 004b92ff1 )
Cybereasonmalicious.7a35da
BaiduMSIL.Trojan.Crypto.a
CyrenW32/Ransom.AY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BZH
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Agent.gen
BitDefenderGen:Variant.MSIL.Lynx.55
NANO-AntivirusTrojan.Win32.Blocker.ckduuh
MicroWorld-eScanGen:Variant.MSIL.Lynx.55
TencentWin32.Trojan.Generic.Sqtj
Ad-AwareGen:Variant.MSIL.Lynx.55
SophosMal/Generic-R + Mal/MSIL-RD
ComodoTrojWare.Win32.Agent.CJR@5aoyq0
BitDefenderThetaGen:NN.ZemsilF.34294.imW@aeWl9Xd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.50076387a35da333
EmsisoftGen:Variant.MSIL.Lynx.55 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.amwt
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.139F626
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.MSIL.Lynx.55
GDataGen:Variant.MSIL.Lynx.55
AhnLab-V3Malware/Win32.Generic.C399470
Acronissuspicious
McAfeeGenericRXKH-HQ!50076387A35D
MAXmalware (ai score=87)
PandaTrj/CI.A
YandexTrojan.Blocker!5uXwpVXid8c
IkarusTrojan.Win32.Pakes
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Dropper.VQB!tr
AVGWin32:KeyloggerX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/Injector.BZH?

MSIL/Injector.BZH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment