Malware

What is “MSIL/Injector.CBB”?

Malware Removal

The MSIL/Injector.CBB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.CBB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

hamo2600.no-ip.org

How to determine MSIL/Injector.CBB?


File Info:

crc32: 49CB643E
md5: 310ec1ef5209e1c3dfa7614e3359f867
name: 310EC1EF5209E1C3DFA7614E3359F867.mlw
sha1: 0c271ece9f9371514bf8d32f92f98e74aacf5f82
sha256: 97f5a19ab32f7c0823fe794bc41ff6d2298dbcebb3dc0627f3b8109c9a1e9174
sha512: cf1b48b91d07fd8285958348e2e9fcc6c4acca96c8ef838c25f791318d451cce90c51dea18f04be7904ee1146ba056f6deee08bc9886fa477ceab9ed339f76b7
ssdeep: 6144:u9C2F8NXC796TB9vj48JqfUo5dQdfz/I5Cp21J+:u3eVQkTrvj45zQR/uu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: How.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: How.exe

MSIL/Injector.CBB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0048ce761 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.40169267
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0048ce761 )
Cybereasonmalicious.f5209e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.CBB
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyTrojan-Ransom.Win32.Blocker.cmfs
BitDefenderTrojan.GenericKD.40169267
NANO-AntivirusTrojan.Win32.Blocker.cifraj
SUPERAntiSpywareTrojan.Agent/Gen-Autorun
MicroWorld-eScanTrojan.GenericKD.40169267
TencentWin32.Trojan.Blocker.Lfgg
Ad-AwareTrojan.GenericKD.40169267
SophosMal/Generic-S
ComodoMalware@#qajy5ppj56pi
BitDefenderThetaGen:NN.ZexaF.34686.rq0@aeEYf8j
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_BLADABINDI.TIAOYBL
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
FireEyeGeneric.mg.310ec1ef5209e1c3
EmsisoftTrojan.GenericKD.40169267 (B)
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
GDataTrojan.GenericKD.40169267
AhnLab-V3Trojan/Win32.Blocker.C236117
McAfeeArtemis!310EC1EF5209
MAXmalware (ai score=97)
VBA32TrojanRansom.Blocker
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_BLADABINDI.TIAOYBL
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!aUVAoPIu9+c
IkarusTrojan.Dropper
FortinetW32/Kryptik.RMO!tr
AVGFileRepMetagen [Malware]

How to remove MSIL/Injector.CBB?

MSIL/Injector.CBB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment