Trojan

Trojan:Win32/CryptInject.MB!MSR (file analysis)

Malware Removal

The Trojan:Win32/CryptInject.MB!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CryptInject.MB!MSR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Hungarian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/CryptInject.MB!MSR?


File Info:

crc32: 3035C13F
md5: d7e81abce9332847471b89e50b241172
name: D7E81ABCE9332847471B89E50B241172.mlw
sha1: a6455d3a4fb9c2e5627dcbf46702a4e16c2492da
sha256: 6141efb6f1598e2205806c5a788e61c489440dfc942984ee1688bb68ad0f18df
sha512: 5847aedd8d283cea10d87c290abca0cf0b4d2c1bbdc102236675539a92fa02c10a756cf61cc55390a6d89cd30951876971c8791f75e8f368a7fae7324c9a112c
ssdeep: 1536:gJ2bp/9/xkVSY5anKZRaTa5BXJMtpEL2bp/9/x:0J6Krd5BkWL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x040e 0x04b0
InternalName: Ridgepieceudtrreu
FileVersion: 1.00
CompanyName: ColdStone
Comments: ColdStone
ProductName: ColdStone
ProductVersion: 1.00
OriginalFilename: Ridgepieceudtrreu.exe

Trojan:Win32/CryptInject.MB!MSR also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Razy
Qihoo-360Win32/Trojan.Generic.HwMAessA
McAfeePWS-FCVE!D7E81ABCE933
MalwarebytesGeneric.Malware/Suspicious
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Razy.4!c
SangforTrojan.Win32.Scarsi.ky
K7AntiVirusTrojan ( 005783491 )
BitDefenderGen:Variant.Razy.845229
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Razy.DCE5AD
BitDefenderThetaGen:NN.ZevbaF.34590.gm0@am4jHKeG
CyrenW32/VBKrypt.ARR.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EOQO
TrendMicro-HouseCallTROJ_GEN.R002C0PBN21
Paloaltogeneric.ml
CynetMalicious (score: 90)
KasperskyTrojan.Win32.Scarsi.awwf
AlibabaTrojan:Win32/Scarsi.f06c82a8
MicroWorld-eScanGen:Variant.Razy.845229
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Variant.Razy.845229
SophosMal/Generic-S
ComodoTrojWare.Win32.UMal.lwcuf@0
F-SecureHeuristic.HEUR/AGEN.1141231
TrendMicroTROJ_GEN.R002C0PBN21
McAfee-GW-EditionPWS-FCVE!D7E81ABCE933
FireEyeGeneric.mg.d7e81abce9332847
EmsisoftTrojan.Injector (A)
IkarusTrojan-Downloader.GuLoader
AviraHEUR/AGEN.1141231
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
MicrosoftTrojan:Win32/CryptInject.MB!MSR
ZoneAlarmTrojan.Win32.Scarsi.awwf
GDataGen:Variant.Razy.845229
AhnLab-V3Trojan/Win32.Injector.C4345752
ALYacTrojan.Agent.GuLoader
MAXmalware (ai score=82)
CylanceUnsafe
PandaTrj/GdSda.A
APEXMalicious
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GuLoader.VHJT!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan:Win32/CryptInject.MB!MSR?

Trojan:Win32/CryptInject.MB!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment