Categories: Malware

About “MSIL/Injector.IXW” infection

The MSIL/Injector.IXW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.IXW virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Accessed credential storage registry keys
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine MSIL/Injector.IXW?


File Info:

name: 8EF03F61B4E417E7F478.mlwpath: /opt/CAPEv2/storage/binaries/7a75e29669ff8ed1bf1c17120355a1fcfd8f48d8f6185b4bc3ac71e4fcc08870crc32: DFF322B1md5: 8ef03f61b4e417e7f47852509a415737sha1: 93ca97eee2296e3721120a1eb15e1f79850836afsha256: 7a75e29669ff8ed1bf1c17120355a1fcfd8f48d8f6185b4bc3ac71e4fcc08870sha512: bd5a5993b28f53fc392312b8516b1254538de1ffca62452ed51a7e99428bf03ece41fefa4aada150d7cb9709bd4b53101cd6394198f9d734d08271fcea7428c1ssdeep: 6144:qEW2vxNsNM1U+89uwEzG3qRQ2kt6YKepdBGvS6YykH2H19G0:hv3EM6FvEkqRQ2k1KUd0vTW+/type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T13164CFC5EBBEBD8AC1AD117740B1568D1431CE01C120CD3736E67BBA0A732D75666E8Bsha3_384: a948a21da636b4af8088a81ccde7f34ca56ef3382d58299d81a6c83cb821dfaec8d869a8f822fff025ef45ba5df7973fep_bytes: ff250020400000000000000000000000timestamp: 2020-04-15 10:44:40

Version Info:

CompanyName: BitTorrent Inc.FileDescription: µTorrentFileVersion: 3.5.5.45628InternalName: uTorrent.exeOriginalFilename: uTorrent.exeLegalCopyright: ©2020 BitTorrent, Inc. All Rights Reserved.ProductName: µTorrentProductVersion: 3.5.5.45628SpecialBuild: stable34 stableTranslation: 0x0409 0x04e4

MSIL/Injector.IXW also known as:

Lionic Trojan.Win32.Generic.m!c
Elastic malicious (high confidence)
FireEye Generic.mg.8ef03f61b4e417e7
McAfee RDN/Generic BackDoor
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor PUP.Win32.Razy.478984
K7AntiVirus Trojan ( 004bc0aa1 )
Alibaba Backdoor:MSIL/Injector.a7257446
K7GW Trojan ( 004bc0aa1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.34062.sm3@a8KAFvhi
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Injector.IXW
APEX Malicious
Paloalto generic.ml
ClamAV Win.Packed.Hpbladabi-6860330-0
Kaspersky UDS:Backdoor.Win32.Generic
NANO-Antivirus Trojan.Win32.Razy.inovyd
Avast Win32:Trojan-gen
Tencent Win32.Trojan.Falsesign.Egom
Comodo Malware@#8exqaj17klzn
DrWeb Trojan.PackedNET.30
TrendMicro TROJ_GEN.R007C0PL421
McAfee-GW-Edition RDN/Generic BackDoor
Sophos Mal/Generic-S
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.7164915.susgen
Avira TR/Injector.fgriv
Microsoft Trojan:Win32/Occamy.C7A
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4800913
Malwarebytes Backdoor.Bladabindi
TrendMicro-HouseCall TROJ_GEN.R007C0PL421
Yandex Trojan.Injector!xUEcuzgP5tk
Ikarus Trojan.MSIL.Injector
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/IXW!tr
AVG Win32:Trojan-gen
Cybereason malicious.1b4e41

How to remove MSIL/Injector.IXW?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

About “Win32/Kryptik.NCA” infection

The Win32/Kryptik.NCA is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Generic.Skintrim.F384AC3E removal guide

The Generic.Skintrim.F384AC3E is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Win32/Injector.Autoit.FXZ removal tips

The Win32/Injector.Autoit.FXZ is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

AIT:Trojan.Nymeria.720 removal

The AIT:Trojan.Nymeria.720 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Malware.AI.3904647846 removal tips

The Malware.AI.3904647846 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Should I remove “Babar.371897”?

The Babar.371897 is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago