Malware

VirTool:MSIL/Injector.DP!bit removal

Malware Removal

The VirTool:MSIL/Injector.DP!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/Injector.DP!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

ikch1120.ddns.net

How to determine VirTool:MSIL/Injector.DP!bit?


File Info:

crc32: F0361523
md5: 74bc18e210da264c7acdeed3482ae0b1
name: 74BC18E210DA264C7ACDEED3482AE0B1.mlw
sha1: 95a08a8ceb57eefe99cc6c5b3de582a5a12cf2ff
sha256: e781bcd0f46b6249cf14cd51bac67076193b81dd82075df67375cc89d92bfacb
sha512: d730a3bff2d1980f44bb8b3e079c7ae36db0207a0fae0d32d5506d303a7e373490fbd406658c583e545e955b8202f440b44e8ec532f59ec0d36a0f33a1fbc068
ssdeep: 6144:Mi6Bk212fj+m7hLgNiINSdM9u3STv4aL+/rV2cWrcmG95iWnIT:p6+2a5BM9i7ayRABCse
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright ? 2016 2p2vnuOfkH5Bo
Assembly Version: 5.46.4.4312
InternalName: 765.exe
FileVersion: 5.46.4.4312
CompanyName: Yr696pmA7z3vg2fn
Comments: Rf00s68l6sa1C
ProductVersion: 5.46.4.4312
FileDescription: RVdy32amUos4p3xt82
OriginalFilename: 765.exe

VirTool:MSIL/Injector.DP!bit also known as:

K7AntiVirusTrojan ( 003af4871 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Starter.6474
CynetMalicious (score: 100)
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 003af4871 )
Cybereasonmalicious.ceb57e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-6931795-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.fbgupd
TencentWin32.Trojan.Generic.Aiim
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34142.tq0@aGA2K!n
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.74bc18e210da264c
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2604A79
MicrosoftVirTool:MSIL/Injector.DP!bit
ZoneAlarmHEUR:Trojan.Win32.Generic
McAfeeGenericRXPS-MK!74BC18E210DA
MAXmalware (ai score=95)
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
YandexTrojan.Agent!/X8yAEtAZfc
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove VirTool:MSIL/Injector.DP!bit?

VirTool:MSIL/Injector.DP!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment