Malware

VirTool:MSIL/Injector.P (file analysis)

Malware Removal

The VirTool:MSIL/Injector.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/Injector.P virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine VirTool:MSIL/Injector.P?


File Info:

name: 32875DE4587936F33141.mlw
path: /opt/CAPEv2/storage/binaries/73836ddad7a45a4ac02fc62f201a8e04d6e5e713b5e3a76fa25adc93d3267ebc
crc32: 8BBD2ABB
md5: 32875de4587936f33141c3968f46310c
sha1: 4531ed96606a3fbba1ba93e52e79b6a74b5275c8
sha256: 73836ddad7a45a4ac02fc62f201a8e04d6e5e713b5e3a76fa25adc93d3267ebc
sha512: 9f9715dd4bb83c170ffea42622732ef0aa5b4731d57bc5865f422b83556bcfc5b8850b466f1c93723d81da0fb920a6b5b5921acd9a5e284292ffbcfa4050b22b
ssdeep: 96:mAnN38TKje0okErTFabGfSFswnIC4rKqCsuVmopDBDrXmWsAGfpmukgmbkfnD7Tv:NNgc1yQswnIk5XRZXfsu5wjMzWk+CW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B71209106BF50235D47FEF325DF66A915AB9B1061D37DE6E0880811B9C23A90CEA3B3D
sha3_384: 1fbaa7c4da5b85b3c8a0c5ef3f9af57fa1f5810c4f2534bd5afa01ca6353a1253dc5897732d2fbe1ced1dab1d5cb7d1a
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-06-06 17:06:13

Version Info:

Translation: 0x0000 0x04b0
Comments: Host Process for Windows Tasks
CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Tasks
FileVersion: 6.1.7601.17514
InternalName: taskhostt.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: taskhostt.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Assembly Version: 6.1.7601.17514

VirTool:MSIL/Injector.P also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.MSILMamut.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILMamut.1885
SkyhighBehavesLike.Win32.Generic.zt
McAfeeArtemis!32875DE45879
ZillyaTrojan.Small.Win32.12145
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003773a91 )
AlibabaVirTool:MSIL/Injector.96fedfbc
K7GWTrojan ( 003773a91 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.ABVR
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Injector.HG
CynetMalicious (score: 99)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILMamut.1885
NANO-AntivirusTrojan.Win32.Small.clnpn
AvastWin32:Malware-gen
TencentMsil.Trojan.Dropper.Lqil
EmsisoftIL:Trojan.MSILMamut.1885 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
VIPREIL:Trojan.MSILMamut.1885
TrendMicroTROJ_GEN.R002C0DA924
FireEyeGeneric.mg.32875de4587936f3
SophosTroj/Fignotok-D
SentinelOneStatic AI – Suspicious PE
GDataIL:Trojan.MSILMamut.1885
JiangminTrojan/MSIL.drx
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/MSIL.Small
Kingsoftmalware.kb.c.1000
XcitiumMalware@#2n806gzjtp6u5
ArcabitIL:Trojan.MSILMamut.D75D
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftVirTool:MSIL/Injector.P
AhnLab-V3Trojan/Win32.RL_Small.C4006298
ALYacIL:Trojan.MSILMamut.1885
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DA924
RisingTrojan.Small!8.A9 (CLOUD)
IkarusTrojan.MSIL.Small
MaxSecureTrojan.Malware.477243.susgen
FortinetW32/Small.AD!tr
BitDefenderThetaGen:NN.ZemsilF.36744.aq0@aaXFkCp
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove VirTool:MSIL/Injector.P?

VirTool:MSIL/Injector.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment