Malware

Should I remove “MSIL/Injector.NBJ”?

Malware Removal

The MSIL/Injector.NBJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.NBJ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

Related domains:

ocsp.verisign.com
evcs-ocsp.ws.symantec.com

How to determine MSIL/Injector.NBJ?


File Info:

crc32: 223CEEF2
md5: a1933d25e1591674f51e76917101f20a
name: A1933D25E1591674F51E76917101F20A.mlw
sha1: 234d37f3a9b8b4ece2bc00105d4dc72ba1ab4f2a
sha256: 52baad9dab220788130ca691baaed3a1f22cc68d913e217bc09f29c2ae822e81
sha512: bd7ea453fa2b0197cbbeec5cd394e50e794284dfb0a73fc3369994491ba3ec15892d03295c349b622d680c199eb4651870f6ad85d7ac705cb6827488f2e527bd
ssdeep: 3072:aRKqejC7g8T4qWwgiBYT4h3dYZXFYfrxITD:aRKqX4fwby8h3KZXFYluD
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014 by Gammadyne
FileVersion: 44.1
CompanyName: Gammadyne
ProductName: Gammadyne Mailer
ProductVersion: 44.1
FileDescription: Installer for Gammadyne Mailer
Translation: 0x0409 0x04e4

MSIL/Injector.NBJ also known as:

K7AntiVirusTrojan ( 0055e39a1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.1932
CynetMalicious (score: 99)
ALYacGen:Heur.MSIL.Abuja.2
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0055e39a1 )
Cybereasonmalicious.5e1591
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.NBJ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Genericrxer-9857196-0
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderGen:Heur.MSIL.Abuja.2
NANO-AntivirusTrojan.Win32.Stealer.dzwzri
MicroWorld-eScanGen:Heur.MSIL.Abuja.2
TencentWin32.Trojan.Falsesign.Llgt
Ad-AwareGen:Heur.MSIL.Abuja.2
SophosMal/Generic-R + Mal/Kryptik-AY
Comodo.UnclassifiedMalware@0
BitDefenderThetaGen:NN.ZemsilF.34686.hm1@a8Q22zci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXER-GI!A1933D25E159
FireEyeGeneric.mg.a1933d25e1591674
EmsisoftGen:Heur.MSIL.Abuja.2 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1114859
eGambitUnsafe.AI_Score_51%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:MSIL/Injector.II!bit
ArcabitTrojan.MSIL.Abuja.2
AegisLabTrojan.Win32.Fareit.i!c
GDataGen:Heur.MSIL.Abuja.2
AhnLab-V3Trojan/Win.Generic.C4443799
McAfeeGenericRXER-GI!A1933D25E159
MAXmalware (ai score=89)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R02DC0DDT21
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.PWS.Fareit!Ed8DKvWviNs
IkarusTrojan.MSIL.Injector
FortinetMSIL/Kryptik.EPT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Injector.NBJ?

MSIL/Injector.NBJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment