Malware

MSIL/Injector.VFU malicious file

Malware Removal

The MSIL/Injector.VFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.VFU virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine MSIL/Injector.VFU?


File Info:

crc32: 2C34FD10
md5: 0ed632ca837fc68c85c6bb16651af7a0
name: upload_file
sha1: 13825d15fcd4bfdef7bdf545a68a34e07a5366f4
sha256: 1e1beae5454f17fedd445159a0f138718c2009df44ac4b05a35ec3971a521f90
sha512: 1f6771437cdc5eefce6e5ade74d1be1a865a2bb7cf5585c40fb32b7633b42c0ca0d619b92d944f92febe46dcab18cf6329c1aa41c88294dabf227f32c83cd0b5
ssdeep: 12288:Htz/FfrcT+awHKB4rx3eL8TxThiLdjVOejeYYPcmi9T1qjuI+WC0iIyL8sXvqb/w:38
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9Thunderbird and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.
Assembly Version: 83.0.0.7599
InternalName: Lime_outlook.exe
FileVersion: 83.0.0.7599
CompanyName: Mozilla Corporation
LegalTrademarks: Thunderbird is a Trademark of The Mozilla Foundation.
Comments: Thunderbird
ProductName: Thunderbird
ProductVersion: 83.0.0.7599
FileDescription: Thunderbird
OriginalFilename: Lime_outlook.exe

MSIL/Injector.VFU also known as:

Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Multi
McAfeePWS-FCSK!0ED632CA837F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.34990052
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D215E7E4
TrendMicroTROJ_GEN.R011C0PK120
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
AlibabaTrojanSpy:Win32/Swotter.9a4623c4
MicroWorld-eScanTrojan.GenericKD.34990052
Ad-AwareTrojan.GenericKD.34990052
EmsisoftTrojan.GenericKD.34990052 (B)
ComodoTrojWare.Win32.Genome.lelyh@0
F-SecureTrojan.TR/AD.Swotter.mewpa
DrWebTrojan.Siggen10.45546
InvinceaMal/Generic-S
McAfee-GW-EditionPWS-FCSK!0ED632CA837F
FireEyeGeneric.mg.0ed632ca837fc68c
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/AD.Swotter.mewpa
Antiy-AVLTrojan[Spy]/MSIL.Noon
MicrosoftTrojan:Win32/Woreflint.A!cl
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataTrojan.GenericKD.34990052
VBA32TScope.Trojan.MSIL
ALYacTrojan.Agent.FormBook
MAXmalware (ai score=83)
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.VFU
TrendMicro-HouseCallTROJ_GEN.R011C0PK120
TencentMsil.Trojan-spy.Noon.Kgc
YandexTrojan.Igent.bUIErp.28
IkarusTrojan.SuspectCRC
eGambitPE.Heur.InvalidSig
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34590.io2@ayvKjrn
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove MSIL/Injector.VFU?

MSIL/Injector.VFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment