Malware

MSIL/Injector.TPZ removal guide

Malware Removal

The MSIL/Injector.TPZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.TPZ virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Injector.TPZ?


File Info:

crc32: 772F009E
md5: 7040b6981c17180aee54a7f5875bac69
name: 7040B6981C17180AEE54A7F5875BAC69.mlw
sha1: 3d556acb7a8ac01df37f09cd0f01fcd5f304fd8d
sha256: c240aaf903293e3b6b166e26f2f288abae3c9f4bb97a8be0064a9d22d9d17c93
sha512: 6a1f2a403550ff9e57b3dfa371ab3d9d1c38991ae3d1a28d71c5c6d8860a477e8503918ba0fb5b9d6a43d571cc87b99738d18cea6f82a816f89b8ce2e32f462f
ssdeep: 1536:qzo4SLIcRVUFjgVcZ0WZUG+D2RmAnNDR:qzo4SLIcRVUFjgVcZ0WZUG+D2RmAnNl
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Monitor inc.
Assembly Version: 1.0.0.0
InternalName: Crypted.exe
FileVersion: 1.0.0.0
CompanyName: Monitor inc.
LegalTrademarks: Monitor inc.
Comments: Monitors system
ProductName: Monitor System
ProductVersion: 1.0.0.0
FileDescription: System Monitor
OriginalFilename: Crypted.exe

MSIL/Injector.TPZ also known as:

K7AntiVirusTrojan ( 004dcb4e1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.Samas.8
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004dcb4e1 )
Cybereasonmalicious.81c171
CyrenW32/MSIL_Troj.UX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.TPZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Ransom.Samas.8
MicroWorld-eScanGen:Variant.Ransom.Samas.8
TencentWin32.Backdoor.Generic.Aeds
Ad-AwareGen:Variant.Ransom.Samas.8
SophosMal/Generic-R + Mal/DotNet-C
ComodoMalware@#29nfj5l1gd45s
BitDefenderThetaGen:NN.ZemsilF.34050.dm0@aSvtg8n
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.7040b6981c17180a
EmsisoftGen:Variant.Ransom.Samas.8 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1118535
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.261A907
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Ransom.Samas.8
GDataGen:Variant.Ransom.Samas.8
AhnLab-V3Malware/Win32.RL_Generic.C3996040
McAfeeArtemis!7040B6981C17
MAXmalware (ai score=84)
PandaTrj/GdSda.A
YandexTrojan.Injector!saWqQm3WyzY
IkarusTrojan-PSW.ILUSpy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.TPZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Generic.HgIASRMA

How to remove MSIL/Injector.TPZ?

MSIL/Injector.TPZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment