Malware

MSIL/Injector.ULP malicious file

Malware Removal

The MSIL/Injector.ULP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.ULP virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Injector.ULP?


File Info:

crc32: E598000E
md5: 2fa538a7532ece17efca5e56635b8cf9
name: stil.exe
sha1: 7bbe80e8d2c95589db509121eaf96e0fa4433f5b
sha256: f8e3fcadc9714cb3a0984735978325cb5f616abc0fff04407ff31030880bf2db
sha512: f2270e5003714517722fa773bbacb3b492ee933ec147de5b87c2d0a05d6d7dabd268b6710a9a7bf5f52b8095337cf47888c342b370e6cce7c30ef1b44f47c353
ssdeep: 6144:Jp9hjG1q/blgso4QRRNID30uD/oQEdObAjGUNSLNdfUmIi2hReQmGTFdsqJhF+4q:JVp
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: 1x43113x431x4334x433A2x4313x43213x433x4321x4311x43234x431114x432x432314x4324x432x432221x4311x430133Ax43331323x431x4323x433x430x432411A32x4304x432A44x433x432x432x433x432x431x4314x433x433x432x4301A11x431x4312x431
Assembly Version: 2.8.3.6
InternalName: BQACAgIAAxkBAAIoXV42rXyQ-Uw-qhMSGnLtbp8NLmPeAAKRBQACrOd4SUiLU0066lPZGAQ.exe
FileVersion: 2.8.3.6
CompanyName: 12x4331x432x433x4313x431x43331x431A442Ax43244x4333x4322x4313x43342121x432x4323x432x43144x430x431Ax432x431221x430x432241x4331124Ax432x4311x432x4322x432x4314A44x433342411A14x4334x431x43341x430x430x433
LegalTrademarks: x4322x4331212x432222Ax432x43314x43042x4332Ax432x433x433x433x4333x430142x431311x430x43011x4332x43221x4314x43333x43331x433Ax432x43111x43214x4314x432232Ax433x4314x430142Ax433x4313x4321x43332x432434x431
Comments: 4x431x431x433x430x431x43344x4332x430x432x43134x4302x433x432A4211322x433x430x4324x432244x4324x432x432x433A24x43332x433A1x430x433x431x4314x431x43142x4332233x4314433x433143A24x433x4332213223x430x433Ax4332
ProductName: 41x433432x4323x433x4331x431x432x431x43021x43312x4314x431x430x4334x4332A2x432x43312x4323x430x431x431x4312x431334x4322431A44x43331x431Ax43221x4333x433x433A13x431231x432A3112133A3x4334x430x433x432x4323
ProductVersion: 2.8.3.6
FileDescription: x432x432x43011AA1x431x433x432x431x4331x4301x433A1344x433x432x432x430Ax4314111x4314x432x432x4331x431x4324x433x4331x4332x433x4332x433x432x432x432x431x431x433x433x43332x4323x43222443x4304x4314x432x43023x4323x43242x431A3111Ax433A
OriginalFilename: BQACAgIAAxkBAAIoXV42rXyQ-Uw-qhMSGnLtbp8NLmPeAAKRBQACrOd4SUiLU0066lPZGAQ.exe

MSIL/Injector.ULP also known as:

MicroWorld-eScanGen:Variant.Razy.605666
FireEyeGeneric.mg.2fa538a7532ece17
Qihoo-360Generic/Trojan.c1b
McAfeeArtemis!2FA538A7532E
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.605666
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Razy.605666
KasperskyUDS:DangerousObject.Multi.Generic
Endgamemalicious (high confidence)
SophosMal/Generic-S
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.605666 (B)
SentinelOneDFI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Razy.D93DE2
Acronissuspicious
ALYacGen:Variant.Razy.605666
MAXmalware (ai score=82)
Ad-AwareGen:Variant.Razy.605666
ESET-NOD32a variant of MSIL/Injector.ULP
eGambitPE.Heur.InvalidSig
FortinetMSIL/Injector.ULP!tr
AVGFileRepMalware
Cybereasonmalicious.8d2c95

How to remove MSIL/Injector.ULP?

MSIL/Injector.ULP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment