Malware

MSIL/Injector.JHR removal

Malware Removal

The MSIL/Injector.JHR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.JHR virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine MSIL/Injector.JHR?


File Info:

name: EBABE28DAB8248A0EFE0.mlw
path: /opt/CAPEv2/storage/binaries/2809f3f56f9b55768d549a93c381a88d9f5752462695b323b6a8b13ebd260809
crc32: D5E6A56C
md5: ebabe28dab8248a0efe041ab79bf3fe0
sha1: 09ff5a18833a1410b4967c9edc33aa05acd25706
sha256: 2809f3f56f9b55768d549a93c381a88d9f5752462695b323b6a8b13ebd260809
sha512: af6b5ccf530b9627c4fc4983ef1eea29dbeb61fc171221e554d12d606064a5a1838f80339c2a8a9d41271ac281a6d7ae443d904614ec67200879c55ea58ab74a
ssdeep: 12288:JJ+K3m9vfi2KeeQD3ukysGBiV12YOWoD:JYX/Ke/37NGBg1k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118A49E23B5EF56AFECFF9536CDE4252943997AC1B428A5FF1246D3848814130EA0BF85
sha3_384: 95809bf27a14fdb64ec171064ebe7c88e9db8880fa3a4ac881015ffa7924e8a6f4fa89e457918d65ef5ce30424a26755
ep_bytes: e80a000000e97affffffcccccccccc8b
timestamp: 2008-04-13 18:32:45

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.2900.5512
Translation: 0x0409 0x04b0

MSIL/Injector.JHR also known as:

LionicTrojan.MSIL.Zapchast.4!c
MicroWorld-eScanGen:Heur.MSIL.Krypt.12
FireEyeGeneric.mg.ebabe28dab8248a0
ALYacGen:Heur.MSIL.Krypt.12
CylanceUnsafe
VIPREGen:Heur.MSIL.Krypt.12
K7AntiVirusTrojan ( 004dd9a41 )
K7GWTrojan ( 004dd9a41 )
Cybereasonmalicious.dab824
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.JHR
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.MSIL.Zapchast.abvll
BitDefenderGen:Heur.MSIL.Krypt.12
NANO-AntivirusTrojan.Win32.Zapchast.dxonas
AvastWin32:Malware-gen
SophosMal/Generic-S
ComodoMalware@#326orxux9in3z
DrWebBackDoor.Bladabindi.1056
McAfee-GW-EditionGenericRXBG-RS!568E64BEC1B5
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.MSIL.Krypt.12 (B)
SentinelOneStatic AI – Malicious SFX
GDataGen:Heur.MSIL.Krypt.12 (2x)
JiangminTrojan.MSIL.dla
GoogleDetected
AviraHEUR/AGEN.1223040
Antiy-AVLTrojan/Generic.ASMalwS.3C54
ArcabitTrojan.MSIL.Krypt.12
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!EBABE28DAB82
MAXmalware (ai score=80)
RisingTrojan.Generic/MSIL@AI.91 (RDM.MSIL:GjaWR0LTb3e4iNdDAucb0w)
YandexTrojan.Zapchast!IOTfsaxYxv0
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.JHR!tr
BitDefenderThetaGen:NN.ZemsilF.34592.iq0@aK!UB@e
AVGWin32:Malware-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_70% (W)

How to remove MSIL/Injector.JHR?

MSIL/Injector.JHR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment