Malware

Should I remove “MSIL/Injector.ERL”?

Malware Removal

The MSIL/Injector.ERL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.ERL virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
nsns7429980.ddns.net
ocsp.pki.goog

How to determine MSIL/Injector.ERL?


File Info:

crc32: A3C396FC
md5: 781965819dccb8a2997f4312ca75ef59
name: 781965819DCCB8A2997F4312CA75EF59.mlw
sha1: ebee06c60daba7678c9d02bf25789018a4ffe2e1
sha256: adcbf4ae4c9187477dccc2e66f2dc2872087de7a32a732ecfe3d604d5cc58de5
sha512: e461a7f903b8546f2cd462c02c5d531fbd7016dd7a2ab1a0fdf7b47a04fe46d7d2623208da01059359de3827686be29043b9b03ff8dc3fec3e831e25a41ee76a
ssdeep: 24576:DaqUUxUxYYUxxxcYyxIcUxyxYx+ZZXUCLxyB1ZjOYx/IYdZZx7Z3xdXZKbYYXyU:jUUxUxYYUxxxcYyxIcUxyxYx+ZZXUCL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: microsoft corporation
Assembly Version: 1.0.0.2
InternalName: microsoft corporation.exe
FileVersion: 1.0.0.0
CompanyName: microsoft corporation
LegalTrademarks: microsoft corporation
Comments: microsoft corporation
ProductName: microsoft corporation
ProductVersion: 1.0.0.0
FileDescription: microsoft corporation
OriginalFilename: microsoft corporation.exe

MSIL/Injector.ERL also known as:

K7AntiVirusTrojan ( 004be6171 )
Elasticmalicious (high confidence)
DrWebBackDoor.Comet.2020
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Samas.1
CylanceUnsafe
ZillyaTrojan.Generic.Win32.304964
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Injector.7106a37f
K7GWTrojan ( 004be6171 )
Cybereasonmalicious.19dccb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.ERL
APEXMalicious
AvastMSIL:GenMalicious-ARE [Trj]
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Ransom.Samas.1
NANO-AntivirusTrojan.Win32.Comet.dzuyac
MicroWorld-eScanGen:Variant.Ransom.Samas.1
TencentMsil.Trojan.Generic.Agbh
Ad-AwareGen:Variant.Ransom.Samas.1
SophosML/PE-A + Troj/MSIL-EGP
BitDefenderThetaGen:NN.ZemsilF.34690.!m0@a8ZRKwd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dz
FireEyeGeneric.mg.781965819dccb8a2
EmsisoftGen:Variant.Ransom.Samas.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_71%
Antiy-AVLTrojan/Generic.ASMalwS.251223C
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ransom.Samas.1
AegisLabTrojan.MSIL.Generic.4!c
GDataGen:Variant.Ransom.Samas.1
McAfeeTrojan-FJIS!781965819DCC
MAXmalware (ai score=99)
VBA32Backdoor.Comet
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
RisingDropper.Generic!8.35E (CLOUD)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.188AB0C!tr
AVGMSIL:GenMalicious-ARE [Trj]
Paloaltogeneric.ml

How to remove MSIL/Injector.ERL?

MSIL/Injector.ERL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment