Malware

How to remove “MSIL:Injector-KH [Trj]”?

Malware Removal

The MSIL:Injector-KH [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Injector-KH [Trj] virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL:Injector-KH [Trj]?


File Info:

crc32: 7C653BE6
md5: d3d70ff76ed6305146910e3912580351
name: D3D70FF76ED6305146910E3912580351.mlw
sha1: c33b9b26863ca7b3bae1bb407c5aac72e25e5682
sha256: dd68fdfc5f9edc7fbabe54be52ccc8b4dd8ffe8055634974353508c1698be93a
sha512: c31d4f4b245f2db752064d1bce1853b4b404885b8a4ce0f935f0efa3378fd3262f2f8e35bc86e1a7deb2964cc5600f5fee7971f70faf8dadc5ff4a9006e985b2
ssdeep: 3072:JEflHh4NpD5GuQ93r4uWY9sMt0kNosbxasPX4+ILn0MDaAU42JTJERd+Zg4A5vO:Jbf5Gu6bx9sW0k+sVagXsLn52JV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: lc6graJ3FP
Assembly Version: 4.2.4.5
InternalName: kkkkk.exe
FileVersion: 4.1.5.x200b0
CompanyName: lc6graJ3FP
LegalTrademarks: nd)hvaQ%LX
Comments: nd)hvaQ%LX RPX 1.3.4399.43191
ProductName: nd)hvaQ%LX
ProductVersion: 4.1.5.x200b0
FileDescription: lc6graJ3FP
OriginalFilename: kkkkk.exe

MSIL:Injector-KH [Trj] also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.d3d70ff76ed63051
McAfeeTrojan-FDWX!D3D70FF76ED6
CylanceUnsafe
VIPRETrojan.MSIL.Zapchast.!pj
Cybereasonmalicious.6863ca
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:Injector-KH [Trj]
ClamAVWin.Packed.Hpbladabi-6860330-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Zapchast.dtyzex
AegisLabTrojan.MSIL.Zapchast.4!c
SophosMal/Generic-S
ComodoMalware@#2h6yo45pqong7
F-SecureHeuristic.HEUR/AGEN.1112944
ZillyaTrojan.Zapchast.Win32.98329
TrendMicroBKDR_HPBLADABI.SM2
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
IkarusTrojan-Dropper.Win32.FrauDrop
JiangminTrojan/MSIL.flgl
AviraHEUR/AGEN.1112944
Antiy-AVLTrojan/MSIL.Packed.Confuser.P
KingsoftWin32.Troj.Zapchast.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bladabindi.R163516
BitDefenderThetaGen:NN.ZemsilF.34804.km0@aa@NUbn
VBA32Trojan.MSIL.Zapchast
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Injector.JFP
TrendMicro-HouseCallBKDR_HPBLADABI.SM2
TencentWin32.Trojan.Generic.Wsjv
YandexTrojan.Zapchast!ceFo+vj+inQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetMSIL/Injecto.58E1!tr
AVGMSIL:Injector-KH [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.6b2

How to remove MSIL:Injector-KH [Trj]?

MSIL:Injector-KH [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment