Malware

How to remove “MSIL:Inject-AF [Trj]”?

Malware Removal

The MSIL:Inject-AF [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Inject-AF [Trj] virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL:Inject-AF [Trj]?


File Info:

crc32: 50BC1F10
md5: accf59a3701b3b28400fa38655f9373f
name: ACCF59A3701B3B28400FA38655F9373F.mlw
sha1: a970038e84749abbbc44d586d2813ca69bc01ba9
sha256: 1bb4fc6446799a94ca00f9ba88f0adb4d2d85de1e8681ab42bbf4ea4a88e18cf
sha512: bd2210de473051b0581f5e038da7fc831bcc735f8256f19ed379ab7e45bf5d7a4cf264422e1e119acc92da7d94d0df5e6feb5e5349b4ccbe53f9131930778ed7
ssdeep: 3072:orsRJYYu71DZ7Myb3udr0U9UrbK69hXiBy/QStGhnDMbYC3wCmSm/S+:hROpDZ93up0nrbK6zXiE/yDM73QT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL:Inject-AF [Trj] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.7
FireEyeGeneric.mg.accf59a3701b3b28
ALYacGen:Heur.MSIL.Krypt.7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cc58b1 )
BitDefenderGen:Heur.MSIL.Krypt.7
K7GWTrojan ( 004cc58b1 )
Cybereasonmalicious.3701b3
BitDefenderThetaAI:Packer.A44F50C01F
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.04c518ac-6899326-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Injector.f3f559e3
RisingDropper.Generic!8.35E (CLOUD)
Ad-AwareGen:Heur.MSIL.Krypt.7
SophosML/PE-A + Mal/MsilDyn-B
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader22.16658
TrendMicroTROJ_GEN.R014C0PBR21
EmsisoftGen:Heur.MSIL.Krypt.7 (B)
IkarusTrojan-Dropper.MSIL
JiangminTrojan/Generic.doav
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.MSIL.Krypt.7
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.MSIL.Krypt.7
CynetMalicious (score: 100)
McAfeeGenericRXKR-WX!ACCF59A3701B
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.ZW
TrendMicro-HouseCallTROJ_GEN.R014C0PBR21
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Injector.KLO!tr
AVGMSIL:Inject-AF [Trj]
AvastMSIL:Inject-AF [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.9A4F.Malware.Gen

How to remove MSIL:Inject-AF [Trj]?

MSIL:Inject-AF [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment