Malware

About “MSIL/Injector.AXE” infection

Malware Removal

The MSIL/Injector.AXE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.AXE virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine MSIL/Injector.AXE?


File Info:

crc32: 4B00B224
md5: 03dbed504744e9229b5b7ac667ba3c19
name: 03DBED504744E9229B5B7AC667BA3C19.mlw
sha1: 1443653a045009cd853a31b377a5f49a0743e01c
sha256: aa146b4d4f04f81f3776413ee680398f1f4959a7a9db7fcfb3020f050007e7ee
sha512: 68a0c986d6fb2e153faa16435211f069b281f2cc8987dacf14afce38d982e0482e911e5f0daea02868003cc2c4ead7f4ae05ae5fe93980545d1f4cd3ad43a118
ssdeep: 3072:zoPxjNdXqog3W0p3agercICTr/xJtPCuC40k+pWUlEaTXaWQ0U9rVv+iICIJBgQ:0xjr0XZWCH+dF1QXL+tNhwwSo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: fafafafa.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: fafafafa.exe

MSIL/Injector.AXE also known as:

Elasticmalicious (high confidence)
ALYacTrojan.MSIL.Basic.3.Gen
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
SymantecBackdoor.ASync!gm
ESET-NOD32a variant of MSIL/Injector.AXE
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.MSIL.Basic.3.Gen
MicroWorld-eScanTrojan.MSIL.Basic.3.Gen
Ad-AwareTrojan.MSIL.Basic.3.Gen
SophosML/PE-A + Mal/MSIL-BM
F-SecureTrojan.TR/Dropper.MSIL.Gen
BitDefenderThetaAI:Packer.53D6F50B1F
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.03dbed504744e922
EmsisoftTrojan.MSIL.Basic.3.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_100%
MicrosoftVirTool:MSIL/Injector.ED
ArcabitTrojan.MSIL.Basic.3.Gen
GDataTrojan.MSIL.Basic.3.Gen
MAXmalware (ai score=82)
MalwarebytesTrojan.Crypt.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.PE!tr
AVGWin32:RATX-gen [Trj]

How to remove MSIL/Injector.AXE?

MSIL/Injector.AXE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment