Malware

Should I remove “MSIL/Injector.FRA”?

Malware Removal

The MSIL/Injector.FRA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.FRA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to identify installed AV products by registry key

How to determine MSIL/Injector.FRA?


File Info:

name: 08848B8AFF3504A96F4F.mlw
path: /opt/CAPEv2/storage/binaries/00ea20823fe2b1da03cdd2855aaf8fd4b05e0c624fd5bdecb724748281caf1b0
crc32: BA44BBB4
md5: 08848b8aff3504a96f4f6766ab8b0e09
sha1: 0a2ee47e1e66c7fc7ff6fb0a6a0d5b580d28e79b
sha256: 00ea20823fe2b1da03cdd2855aaf8fd4b05e0c624fd5bdecb724748281caf1b0
sha512: b029083a253600ed8cd76ee115b5a1a55d267a43e93995f36258ec321129e500e9ee9947be574226e0682d000719e96ef3e397014f59d7f11dc2b0eb3ca296dc
ssdeep: 6144:YBLXwttTLdr8ySfW/itoz4d5cSlS3btdYTg6Jh2hH:UXwtDrY9o+5/Q3b0Tg6X+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1386412DAD954C495F719ABB800AEBB546AF47D6F4301A57B36D01928CDF22022CBB43F
sha3_384: 407e16377cccf724e56d9e2c713f5ab8ad5a7f6a8e0a730343942847ddbba4acad493036f5b81911036ef9429d0f2b76
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-10-06 13:33:40

Version Info:

Translation: 0x0000 0x04b0
Comments: SPViFvlX
FileDescription: SPViFvlX
FileVersion: 3.3.84.6
InternalName: AQPLsgyXnhaN.exe
LegalCopyright: (C) SPViFvlX
OriginalFilename: AQPLsgyXnhaN.exe
ProductVersion: 3.3.84.6
Assembly Version: 2.5.1.3

MSIL/Injector.FRA also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.m94V
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Mardom.MN.12
FireEyeGeneric.mg.08848b8aff3504a9
CAT-QuickHealTrojanPWS.Zbot.D3
ALYacGen:Trojan.Mardom.MN.12
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduMSIL.Trojan.Injector.a
VirITTrojan.Win32.MSIL5.PBS
CyrenW32/Zbot.JWDZ-1890
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Injector.FRA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1194358
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Mardom.MN.12
NANO-AntivirusTrojan.Win32.FRG.dgitwk
SUPERAntiSpywareTrojan.Agent/Gen-FakePDF
AvastSf:Injector-AP [Trj]
RisingMalware.FakePDF/ICON!1.9C3A (CLASSIC)
Ad-AwareGen:Trojan.Mardom.MN.12
EmsisoftGen:Trojan.Mardom.MN.12 (B)
ComodoMalware@#263hrmusr9e8l
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.Panda.5676
VIPREGen:Trojan.Mardom.MN.12
TrendMicroTROJ_FORUCON.BME
McAfee-GW-EditionPWSZbot-FAEN!08848B8AFF35
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Msil-ANY
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Mardom.MN.12
JiangminTrojan.Generic.uznw
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Mardom.MN.12
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 99)
Acronissuspicious
McAfeePWSZbot-FAEN!08848B8AFF35
TrendMicro-HouseCallTROJ_FORUCON.BME
TencentMalware.Win32.Gencirc.1149895c
YandexTrojan.PWS.Panda!yon4U+m0fHU
IkarusBackdoor.Androm
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.FPV!tr
BitDefenderThetaGen:NN.ZemsilF.34592.um3@auM0a3f
AVGSf:Injector-AP [Trj]
Cybereasonmalicious.aff350
PandaTrj/Zbot.AB

How to remove MSIL/Injector.FRA?

MSIL/Injector.FRA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment