Malware

About “MSIL/Injector.APU” infection

Malware Removal

The MSIL/Injector.APU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.APU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine MSIL/Injector.APU?


File Info:

name: 14B026C189683CE558B6.mlw
path: /opt/CAPEv2/storage/binaries/9125c7703d7dd8c23ea5fd496a2b7b5e779ba8ce4198bd1c5cb49a2b3425ac01
crc32: C8C29782
md5: 14b026c189683ce558b62ac269f8fb43
sha1: 67b0785e61e2313fe126d72b1a110a6e4547781d
sha256: 9125c7703d7dd8c23ea5fd496a2b7b5e779ba8ce4198bd1c5cb49a2b3425ac01
sha512: bb39f6466142a1984c6db30eae232a587914bb435e648791b58284876e5c64cdb688c90fdc29bd16572e01644fde0e92a27d74f05a98df0f8a845a30990afab4
ssdeep: 1536:tGlifbUmtFzPp1khtQhn+FkHVzMlzJjNkuxzub:dwmtJp6Eh+FuVghJBlc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11653E1D4879C4142EB325DF087CCE9193F7C9B82551293866E98E1771F97FC1CA128B6
sha3_384: 544bc21defc39dc3cb5867108d2e6a4e1d57c2241f3f9c1c4ac48bafcd1cf032c2d2cb87ff1a40b950e0f078dd15c3da
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-06-02 17:48:59

Version Info:

Translation: 0x0000 0x04b0
Comments: vNgNFfS
FileDescription: CEAVPDBtf
FileVersion: 1.0.0.0
InternalName: svshost.exe
LegalCopyright: czQCeBqrUqla
LegalTrademarks: zFQbTevltGZsQL
OriginalFilename: svshost.exe
ProductName: dvHqibvLSComB
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Injector.APU also known as:

AVGMSIL:Dropper-KX [Drp]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.RX.dm2@XO3CBVfi
FireEyeGeneric.mg.14b026c189683ce5
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWUnwanted-Program ( 700000121 )
K7AntiVirusUnwanted-Program ( 700000121 )
BitDefenderThetaAI:Packer.E2B98E761F
ESET-NOD32a variant of MSIL/Injector.APU
APEXMalicious
ClamAVWin.Trojan.MSIL-9
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.RX.dm2@XO3CBVfi
NANO-AntivirusTrojan.Win32.Crypt.dkgbvc
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Falint
AvastMSIL:Dropper-KX [Drp]
Ad-AwareGen:Trojan.Heur.RX.dm2@XO3CBVfi
EmsisoftGen:Trojan.Heur.RX.dm2@XO3CBVfi (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebWin32.HLLW.Autoruner.47443
VIPREGen:Trojan.Heur.RX.dm2@XO3CBVfi
SophosML/PE-A + Mal/MSIL-AW
IkarusWorm.Win32.Ainslot
JiangminTrojan/MSIL.bvd
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3303
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Heur.RX.EBB80F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan-Dropper.Yeahrite.A
GoogleDetected
Acronissuspicious
ALYacGen:Trojan.Heur.RX.dm2@XO3CBVfi
MAXmalware (ai score=80)
YandexTrojan.Gendal!MkUeSznI/OI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.APU!tr
Cybereasonmalicious.189683
PandaGeneric Malware

How to remove MSIL/Injector.APU?

MSIL/Injector.APU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment