Malware

VirTool:MSIL/Injector.DU!bit information

Malware Removal

The VirTool:MSIL/Injector.DU!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/Injector.DU!bit virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine VirTool:MSIL/Injector.DU!bit?


File Info:

name: BE9FCF3C088F2030A151.mlw
path: /opt/CAPEv2/storage/binaries/3cdc9042427ccc7c1432e15bc7b0ae729eaf6c2d7c603e2a49ce3ba8340cbea0
crc32: F0F73FA8
md5: be9fcf3c088f2030a1513ff9d3bb9afd
sha1: e68835f68d6147c7bbbb2dfbdc3541e77f5ba909
sha256: 3cdc9042427ccc7c1432e15bc7b0ae729eaf6c2d7c603e2a49ce3ba8340cbea0
sha512: 582a53fe1c7f310fa740313295c061e31bcd9f339aa51f04da1d3cd8175849f41fb255279cab036ee23695d56af7da4ec88c490ea05e697a14b664b9264c30fc
ssdeep: 12288:iUnfDwC+9b9A9u+qvuK960iJM05x++l9Q+:tnJUb9Z+vw60Enxbl9Q+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CBC4E1627596A49CC41D0A3541B790C2B6F313CA3EB58E0D749F931C1E13B2BAB49B7E
sha3_384: de2a44c21d3963ea79b10151ae91e70fc1ab68c8689c294a2c75f66139fa49873ebd85402ca3d0f1d807177e1198e9f0
ep_bytes: ff250020400000000000000000000000
timestamp: 1993-09-18 07:04:01

Version Info:

Translation: 0x0000 0x04b0
Comments: umagumihorosinezibixiqup
CompanyName: CMIE ROMANIA SRL
FileDescription: Antiphishing Toolbar Button
FileVersion: 3.12.26.4
InternalName: pf.exe
LegalCopyright: Copyright © 2018 CMIE ROMANIA SRL
OriginalFilename: pf.exe
ProductName: Antiphishing Toolbar Button
ProductVersion: 3.12.26.4
Assembly Version: 0.0.0.0

VirTool:MSIL/Injector.DU!bit also known as:

DrWebTrojan.VbCrypt.150
MicroWorld-eScanGen:Heur.MSIL.Pretoria.1
McAfeeGenericRXHC-IE!BE9FCF3C088F
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005480131 )
K7GWTrojan ( 005480131 )
Cybereasonmalicious.c088f2
BitDefenderThetaGen:NN.ZemsilF.34806.Im2@am@sQRo
CyrenW32/MSIL_Troj.PS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.UGC
APEXMalicious
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderGen:Heur.MSIL.Pretoria.1
AvastWin32:Trojan-gen
Ad-AwareGen:Heur.MSIL.Pretoria.1
EmsisoftGen:Heur.MSIL.Pretoria.1 (B)
F-SecureHeuristic.HEUR/AGEN.1216684
VIPREGen:Heur.MSIL.Pretoria.1
TrendMicroBKDR_HPBLADABINDI.SMZ
McAfee-GW-EditionGenericRXHC-IE!BE9FCF3C088F
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.be9fcf3c088f2030
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.MSIL.Pretoria.1
JiangminBackdoor.MSIL.cbki
AviraHEUR/AGEN.1216684
Antiy-AVLTrojan[Backdoor]/MSIL.Androm
ArcabitTrojan.MSIL.Pretoria.1
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
MicrosoftVirTool:MSIL/Injector.DU!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSIL.C2411802
Acronissuspicious
ALYacGen:Heur.MSIL.Pretoria.1
MAXmalware (ai score=85)
MalwarebytesSpyware.PasswordStealer.MSIL.Generic
TrendMicro-HouseCallBKDR_HPBLADABINDI.SMZ
YandexTrojan.Injector!g00/Iz1Gndo
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.QRG!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VirTool:MSIL/Injector.DU!bit?

VirTool:MSIL/Injector.DU!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment