Malware

MSIL/Injector.EPX malicious file

Malware Removal

The MSIL/Injector.EPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.EPX virus can do?

  • Injection (inter-process)
  • Executable code extraction
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Clears web history

How to determine MSIL/Injector.EPX?


File Info:

crc32: EDB0A8C0
md5: 655cab222083c5b7abe7488bdc1b3a0d
name: 655CAB222083C5B7ABE7488BDC1B3A0D.mlw
sha1: 6a75ee1b232eff745e69325b026a62aa92d32437
sha256: 5c826388fa62f70e2126733faa806f948993289a9645544d98d9e788989592f8
sha512: 9ecbc7918e10f8f1e567e39d08db2acfd704c2746c6c1478132b1b3bb0376d5827c8e83100c91f2022febe50fbd4bce5138a8d17552d95fb8ad55f57da610f81
ssdeep: 12288:gf+EwZv6YLzsQFCIx2UbFIKGEtawksUCLYSmmNiNf:gV2w42UbHtvka1ix
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: chromisko.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: chromisko.exe

MSIL/Injector.EPX also known as:

K7AntiVirusTrojan ( 0053564e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.16403
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.449411
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0053564e1 )
Cybereasonmalicious.22083c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.EPX
APEXMalicious
AvastMSIL:GenMalicious-BNB [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.flwy
BitDefenderGen:Variant.Razy.449411
NANO-AntivirusTrojan.Win32.EPX.dhxvjt
MicroWorld-eScanGen:Variant.Razy.449411
TencentWin32.Trojan.Blocker.Wnmq
Ad-AwareGen:Variant.Razy.449411
SophosMal/Generic-R + Troj/MSIL-AAG
ComodoTrojWare.MSIL.Ceatrg.RJIK@5nq15g
BitDefenderThetaGen:NN.ZemsilF.34688.Dm0@aClLIVd
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R03BC0RE121
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.655cab222083c5b7
EmsisoftGen:Variant.Razy.449411 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1142120
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Malagent!gmb
ZoneAlarmTrojan-Ransom.Win32.Blocker.flwy
GDataGen:Variant.Razy.449411
TACHYONTrojan/W32.DN-Blocker.475136
AhnLab-V3Trojan/Win.Generic.C4442826
Acronissuspicious
McAfeeArtemis!655CAB222083
MAXmalware (ai score=87)
VBA32Hoax.Blocker
MalwarebytesBackdoor.Agent.DCGen
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Blocker.R03BC0RE121
RisingTrojan.Win32.Generic.1750DB81 (C64:YzY0OnBmcsY5JH/s)
YandexTrojan.Blocker!wITrNG47ieM
IkarusTrojan.MSIL6
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.EPX!tr
AVGMSIL:GenMalicious-BNB [Trj]
Paloaltogeneric.ml

How to remove MSIL/Injector.EPX?

MSIL/Injector.EPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment