Malware

MSIL/Injector.GQV removal tips

Malware Removal

The MSIL/Injector.GQV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.GQV virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MSIL/Injector.GQV?


File Info:

name: EAD5B79E52DFB520F940.mlw
path: /opt/CAPEv2/storage/binaries/d19eb75cf34c34bb2204ec30928791ab181a78cc4acd699ecdc40840d174ddd3
crc32: 3CEB08AA
md5: ead5b79e52dfb520f940b3f7bc4ba181
sha1: 7c7229fbc02225eea5dbd41ed40ec3b840d4305b
sha256: d19eb75cf34c34bb2204ec30928791ab181a78cc4acd699ecdc40840d174ddd3
sha512: 05900e2517e0889bef08804fae079e5028b5b9afdd2aab627fe52d2aee14bfb8cffa8c2e392d248836fd54dbc27606ffe1de278641c2c670bfd1e80c2ae22192
ssdeep: 12288:ZYjlN6kDdNDGnmbUE7mXuaKC+doIhJZ0r5Q5frU:ZYjlN3Ddsm/z1xU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192A4CF4222CCC1A6C4B93BB5F35139D1CBDCBEF648DECB50D8B686856C518907E2E5CA
sha3_384: 168618f7be3fb6bd8934c6245b4e85d023dea58cf154ad8a8d39544d22893eb1fea3535d06a60a310174131a83077f3e
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-12-11 21:46:38

Version Info:

FileDescription: Microsoft Ram OP
Translation: 0x0000 0x04b0

MSIL/Injector.GQV also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTool.MailPassView.236
MicroWorld-eScanGen:Trojan.Mardom.MN.9
CAT-QuickHealTrojan.GenericFC.S19436204
SkyhighPWSZbot-FAIB!EAD5B79E52DF
McAfeePWSZbot-FAIB!EAD5B79E52DF
Cylanceunsafe
ZillyaTrojan.Generic.Win32.358675
SangforSuspicious.Win32.Save.a
K7AntiVirusUnwanted-Program ( 700000121 )
AlibabaTrojan:MSIL/Injector.e3be074d
K7GWUnwanted-Program ( 700000121 )
Cybereasonmalicious.bc0222
ArcabitTrojan.Mardom.MN.9
BitDefenderThetaGen:NN.ZemsilF.36680.Dm2@a0VLvrk
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Injector.GQV
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Mardom.MN.9
NANO-AntivirusTrojan.Win32.MailPassView.etfzzw
AvastWin32:RATX-gen [Trj]
TencentWin32.Trojan.FalseSign.Rimw
EmsisoftGen:Trojan.Mardom.MN.9 (B)
F-SecureHeuristic.HEUR/AGEN.1304598
VIPREGen:Trojan.Mardom.MN.9
SophosTroj/dnCreek-D
IkarusTrojan.MSIL.Crypt
JiangminTrojan.Generic.cklpf
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1304598
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.c.1000
XcitiumMalware@#1ziw7786xg1s
MicrosoftTrojan:MSIL/Toauta!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Mardom.MN.9
VaristW32/MSIL_Agent.AG.gen!Eldorado
AhnLab-V3Spyware/Win32.Limitail.R135124
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.Injector!9iFOlDNvNhQ
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Injector.FZD!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Injector.GQV?

MSIL/Injector.GQV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment