Backdoor

About “Backdoor:MSIL/CryptInject!MTB” infection

Malware Removal

The Backdoor:MSIL/CryptInject!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/CryptInject!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Backdoor:MSIL/CryptInject!MTB?


File Info:

crc32: B95C4C25
md5: da63906ad0b95cfd9ba1c0c411d1035b
name: PornHub-Account-Checker-v1.0.02.exe
sha1: 573a6f2484c01b35cf2eb176c33e2abb8ef2e0e8
sha256: 135da98e94f1a706da756a78eaf694148a556f72f1230f006d0f3b37023eaede
sha512: b378516ace5431f00097192df3410b0669cd042572b887e07aa7010a97cf5b09c6090664dfdb679cb441b664b9aab588d2539755e17cadb7725d66551a97c168
ssdeep: 24576:Hb926z7uhx7h8vOd7dDFO0LcTRrpQzES3ERMa:HfzShDzd7Dorp/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor:MSIL/CryptInject!MTB also known as:

MicroWorld-eScanGen:Variant.Razy.556680
FireEyeGeneric.mg.da63906ad0b95cfd
CAT-QuickHealTrojan.FkpFC.S8707126
McAfeeArtemis!DA63906AD0B9
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056081c1 )
BitDefenderGen:Variant.Razy.556680
K7GWTrojan ( 0056081c1 )
Cybereasonmalicious.484c01
TrendMicroTrojanSpy.MSIL.NANOCORE.SMQ.hp
BitDefenderThetaGen:NN.ZemsilF.34108.qnW@aKi6vAyi
ESET-NOD32a variant of MSIL/Kryptik.SQK
TrendMicro-HouseCallTrojanSpy.MSIL.NANOCORE.SMQ.hp
GDataGen:Variant.Razy.556680
AlibabaBackdoor:MSIL/CryptInject.0ced7e55
RisingBackdoor.CryptInject!8.10C59 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.556680 (B)
F-SecureTrojan.TR/Dropper.Gen2
DrWebTrojan.PackedNET.147
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUPXBZ.tc
SentinelOneDFI – Malicious PE
Trapminesuspicious.low.ml.score
APEXMalicious
AviraTR/Dropper.Gen2
MicrosoftBackdoor:MSIL/CryptInject!MTB
ArcabitTrojan.Razy.D87E88
AhnLab-V3Malware/Win32.RL_Generic.C3464386
Acronissuspicious
ALYacGen:Variant.Razy.556680
MAXmalware (ai score=80)
Ad-AwareGen:Variant.Razy.556680
MalwarebytesTrojan.HCrypt.Generic
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.SQK!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.030C.Malware.Gen

How to remove Backdoor:MSIL/CryptInject!MTB?

Backdoor:MSIL/CryptInject!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment