Malware

What is “MSIL/Injector.GIK”?

Malware Removal

The MSIL/Injector.GIK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.GIK virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine MSIL/Injector.GIK?


File Info:

name: D22BB59E14C309C23BFD.mlw
path: /opt/CAPEv2/storage/binaries/66795bef53dc41f4b03a37894671c6bbcaac1448c69d8e27b2c02e402cae2b7a
crc32: 43CB8B9D
md5: d22bb59e14c309c23bfd09d876384462
sha1: 3e5b781a131a01bad2413fe3359bff15090b879d
sha256: 66795bef53dc41f4b03a37894671c6bbcaac1448c69d8e27b2c02e402cae2b7a
sha512: 5733829f228cf847c45d59462b46a02b162a24454e04fa3747adac051beef7157098e77b84fe4a869ab2407ba1cb8a132a62c61bb8100534b4fba77a927063c5
ssdeep: 3072:RchOWdoZkjx+FXMk8LHRAuKIsroj+qIYRDEkrpUcn9RwB/DdlJFr30HM8baRYX2H:ahYW+xdWDLrqsv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBF3D7D6FAEDDEFAE58AD57C9D8331500AE146736BC0CE2ADCA110165C61C26F206CD2
sha3_384: 46e2b2428d57f29b009721d32e0a86b6c813da1f87fe749fef7bc4d68cb588a846a6e65eb03e4a851f4f1dcf6d888737
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-09-28 16:02:29

Version Info:

Translation: 0x0000 0x04b0
Comments: 3e141cbd-22fe-4f72-a23d-50aca10850a5
CompanyName: 3e141cbd-22fe-4f72-a23d-50aca10850a5
FileDescription: 3e141cbd-22fe-4f72-a23d-50aca10850a5
FileVersion: 1.0.0.0
InternalName: ¢¢™‰€™Ï™Þ™™€Ï™‰œ™‰ŒŒ™‰Þ€‰¢¢€™€.exe
LegalCopyright: 3e141cbd-22fe-4f72-a23d-50aca10850a5
LegalTrademarks: 3e141cbd-22fe-4f72-a23d-50aca10850a5
OriginalFilename: ¢¢™‰€™Ï™Þ™™€Ï™‰œ™‰ŒŒ™‰Þ€‰¢¢€™€.exe
ProductName: 3e141cbd-22fe-4f72-a23d-50aca10850a5
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Injector.GIK also known as:

LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.d22bb59e14c309c2
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bf2a71 )
AlibabaTrojan:MSIL/Injector.6f996ff3
K7GWTrojan ( 004bf2a71 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Troj.AAB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.GIK
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Bulz.hyfrqy
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Sgil
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebTrojan.PackedNET.343
ZillyaTrojan.Injector.Win32.775856
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
JiangminTrojan.Generic.ggjbq
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/MSIL.Injector
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Win-Trojan/MSILKrypt09.Exp
McAfeeArtemis!D22BB59E14C3
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.96 (RDM.MSIL2:emM2o89D3E9jx3sSuCIchg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Agent.AQJ!tr
BitDefenderThetaGen:NN.ZemsilF.36662.kq0@aqRsAUm
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove MSIL/Injector.GIK?

MSIL/Injector.GIK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment