Trojan

About “TrojanDropper:Win32/CrptInject!MSR” infection

Malware Removal

The TrojanDropper:Win32/CrptInject!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/CrptInject!MSR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Deletes executed files from disk
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanDropper:Win32/CrptInject!MSR?


File Info:

name: 1706C64156D873EBBD0C.mlw
path: /opt/CAPEv2/storage/binaries/d439a3ce7353ef96cf3556abba1e5da77eac21fdba09d6a4aad42d1fc88c1e3c
crc32: E71281C5
md5: 1706c64156d873ebbd0c6ecac95fec39
sha1: be450cd1fab1b708ac1de209224e0d7f7adc0fae
sha256: d439a3ce7353ef96cf3556abba1e5da77eac21fdba09d6a4aad42d1fc88c1e3c
sha512: 260e243510f7b342773e1e0d7714c228e6a1c809e718e326808b753d39e0e325b6f9aae97b9264de9d1af240e995f2c67e336cd48214fb8a62217e347b36e6b1
ssdeep: 6144:LOYGXaPNxdgSdcq2pVZPOJHAbKL2grda6pZhXnSg0ohhqmcf:fGqN/XdctpVtkb2grU6prnSg0oDJcf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13884D102BAC188B2D5731A325939A7156E7D7D202F24DA2FB3E44D7DEE315806235BB3
sha3_384: 21db2615f043a516263abad423443be2a0e31203df4b3e46447f3c5b8a4509c76d49f4e54d97a8b55d62d2f77343af21
ep_bytes: e85a040000e98efeffff3b0d68d64300
timestamp: 2019-12-05 07:37:23

Version Info:

0: [No Data]

TrojanDropper:Win32/CrptInject!MSR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.DynamicWrapperX.4!c
MicroWorld-eScanTrojan.GenericKD.66953938
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeRDN/Generic Downloader.x
Cylanceunsafe
SangforDropper.Win32.Dynamicwrapperx.Vsws
CrowdStrikewin/malicious_confidence_60% (W)
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
ArcabitTrojan.Generic.D3FDA2D2
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DynamicWrapperX.A potentially unsafe
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Dynamicwrapperx-10006163-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.66953938
NANO-AntivirusRiskware.Win32.DynamicWrapperX.jyjzbn
AvastScript:SNH-gen [Drp]
TencentScript.Trojan-Downloader.Generic.Uimw
EmsisoftTrojan.GenericKD.66953938 (B)
F-SecurePrivacyRisk.SPR/DynamicWrapperX.A
DrWebTrojan.AVKill.63950
VIPRETrojan.GenericKD.66953938
TrendMicroTROJ_FRS.0NA103EA23
SophosMal/Generic-S (PUA)
IkarusTrojan.DynWrapper
WebrootW32.Trojan.GenKD
VaristW32/Trojan.UATC-1233
AviraSPR/DynamicWrapperX.A
Antiy-AVLTrojan/JS.Malgent
KingsoftWin32.Trojan.DelShad.a
XcitiumMalware@#mxd2j7z128o6
MicrosoftTrojanDropper:Win32/CrptInject!MSR
ViRobotTrojan.Win.Z.Agent.390295
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.66953938
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R587965
MalwarebytesTrojan.Agent.RAR
TrendMicro-HouseCallTROJ_FRS.0NA103EA23
RisingTrojan.Agent/JS!8.11351 (TOPIS:E0:vkgCc3tKvMO)
YandexTrojan.Igent.bTLlBh.34
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.MU
AVGScript:SNH-gen [Drp]
DeepInstinctMALICIOUS

How to remove TrojanDropper:Win32/CrptInject!MSR?

TrojanDropper:Win32/CrptInject!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment