Malware

MSIL/Injector.VVR malicious file

Malware Removal

The MSIL/Injector.VVR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.VVR virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Injector.VVR?


File Info:

name: 5EFC2A888A45BDB12D0B.mlw
path: /opt/CAPEv2/storage/binaries/a939e62321414df3d75080bae0b1107f1e6915fc39e01e1cdcd625079fff553c
crc32: AE971CE4
md5: 5efc2a888a45bdb12d0b145d3c0b0817
sha1: 947c887f29bfb6b9c4ccf1e9fc640a46fe177a15
sha256: a939e62321414df3d75080bae0b1107f1e6915fc39e01e1cdcd625079fff553c
sha512: 2455cd460b1b93a490458b39cf8253fdc3c2d1930119fae8892078c4d2452440bf0c62fee81463ddf944cdb6aaf529c0072e3a6b2ba9d27d7aeeb841eeacfc2a
ssdeep: 192:7IhYJ+frUf0HxBnEBFNxKcUx6Koqv6A8nIFO5bhece/6vkYcV6GxD2llKE14/KQ:YUnocZKQ1Q/YkYcV6GxDqlK4IKQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16E52085032E420FDD522C576DA596E05AB36A5FF6B4B021B344F0A2E7F6E451CB232F2
sha3_384: 0290d7acb3003186c49b57660453107c2bf8b4b8809a0bfe2928019bf5edf6047f93dd88ec687f535fb5746e23e17a38
ep_bytes: ff250020400000000000000000000000
timestamp: 2062-11-26 11:56:01

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: OnionDownloader
FileVersion: 1.0.0.0
InternalName: OnionDownloader.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: OnionDownloader.exe
ProductName: OnionDownloader
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Injector.VVR also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.5efc2a888a45bdb1
ALYacTrojan.GenericKDZ.82968
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1383130
SangforTrojan.MSIL.Upatre.gen
K7AntiVirusTrojan ( 0058d4101 )
AlibabaTrojanDownloader:MSIL/Upatre.557b8476
K7GWTrojan ( 0058d4101 )
Cybereasonmalicious.f29bfb
CyrenW32/Trojan.MKBM-6534
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.VVR
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.MSIL.Upatre.gen
BitDefenderTrojan.GenericKDZ.82968
MicroWorld-eScanTrojan.GenericKDZ.82968
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Upatre.Tbtc
EmsisoftTrojan.GenericKDZ.82968 (B)
DrWebTrojan.DownLoader44.34126
TrendMicroTROJ_GEN.R002C0PAR22
McAfee-GW-EditionGenericRXRN-ZN!5EFC2A888A45
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Injector.rruna
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.351778D
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Upatre.gen
GDataTrojan.GenericKDZ.82968
AhnLab-V3Trojan/Win.Generic.C4925686
McAfeeGenericRXRN-ZN!5EFC2A888A45
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.DCRat.Drop
TrendMicro-HouseCallTROJ_GEN.R002C0PAR22
RisingTrojan.Generic/MSIL@AI.96 (RDM.MSIL:LY1vgFGmGOwkWc/7mA/Thw)
YandexTrojan.Injector!dIr3+H871yo
IkarusTrojan.MSIL.Injector
FortinetMSIL/VVR!tr
BitDefenderThetaGen:NN.ZemsilCO.34182.am0@amb8sFg
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/Injector.VVR?

MSIL/Injector.VVR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment