Malware

MSIL/Injector.JFU (file analysis)

Malware Removal

The MSIL/Injector.JFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.JFU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares

How to determine MSIL/Injector.JFU?


File Info:

crc32: B33F5BFE
md5: 6457dc2fd69d93ce996990e0b90fe7ed
name: 6457DC2FD69D93CE996990E0B90FE7ED.mlw
sha1: 7d92f216e63316b0a4a5a7383ba1373f5b272487
sha256: 35673c57d9695d2b0ae68c1b395f8ac9875c6e226dda650c59233d97f7433878
sha512: 75344ad4a93eaa7b6869603387f4559bebb98515f2635dcb5e6bd46dc59cfcfe2125f4ef7f32e21bd0ce97b5aba6e842535048a241d678f7e9706f2b18937697
ssdeep: 6144:Ff34GbZ1j+iIY/pPMyIEAkE6MAmSkQssGWBjSP:FfI8yixkHk7M+TUWBO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2013 - 2015
InternalName: hkmsvc
FileVersion: 15.0.30274.5111
CompanyName:
ProductName: hkmsvc
ProductVersion: 15.0.30373.5119
FileDescription: Health Key and Certificate Management
OriginalFilename: hkmsvc.exe
Translation: 0x0409 0x04b0

MSIL/Injector.JFU also known as:

K7AntiVirusTrojan ( 004be0971 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.1932
CynetMalicious (score: 99)
ALYacGen:Heur.MSIL.Androm.9
CylanceUnsafe
ZillyaTrojan.Generic.Win32.336118
SangforBackdoor.MSIL.Androm.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:MSIL/Androm.aae20ad2
K7GWTrojan ( 004be0971 )
Cybereasonmalicious.fd69d9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.JFU
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderGen:Heur.MSIL.Androm.9
NANO-AntivirusTrojan.Win32.Stealer.fjxots
MicroWorld-eScanGen:Heur.MSIL.Androm.9
TencentMsil.Backdoor.Androm.Wncp
Ad-AwareGen:Heur.MSIL.Androm.9
SophosMal/Generic-R + Troj/MSIL-COW
ComodoTrojWare.MSIL.Fareit.AE@5t24kr
BitDefenderThetaGen:NN.ZemsilF.34110.pm0@aiJmwJni
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PHP21
McAfee-GW-EditionTrojan-FGFA!6457DC2FD69D
FireEyeGeneric.mg.6457dc2fd69d93ce
EmsisoftGen:Heur.MSIL.Androm.9 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1122304
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28FD646
MicrosoftTrojan:Win32/Occamy.C35
GDataGen:Heur.MSIL.Androm.9
AhnLab-V3Spyware/Win32.Zbot.R143640
McAfeeTrojan-FGFA!6457DC2FD69D
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Agent.PDL
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PHP21
YandexTrojan.Agent!i6eJTI+L5LI
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.JFU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove MSIL/Injector.JFU?

MSIL/Injector.JFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment