Trojan

What is “Trojan:Win32/InjectorGen.C!MSR”?

Malware Removal

The Trojan:Win32/InjectorGen.C!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/InjectorGen.C!MSR virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/InjectorGen.C!MSR?


File Info:

crc32: B90B6027
md5: e181b306c65a5072c6e133dd5c545461
name: E181B306C65A5072C6E133DD5C545461.mlw
sha1: 7e2cf8dfe4d0602c613d9e5a92497a7e7ed0c154
sha256: 01a2c4a3dd82f6e3fc651261af69dc942692b1d0df9ab07136eddcdb78bd367e
sha512: 530549b45a0e51fa289f1d5aea9f771091998b687255d4858b02c624ab7f42b09c2ca11d79e50433a3e10f3069423fa02b2b089a86e9c5f38095159321ba458d
ssdeep: 12288:aKzACV6yowXNlK4Q4kAEzZsaAxSFdTrB4WzptEp9lKTc4u:aK0UXNdk3zmKfZ4Wz41Kdu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.9600.16384 (winblue_rtm.130821-1623)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16384
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan:Win32/InjectorGen.C!MSR also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.260
MicroWorld-eScanTrojan.GenericKD.33275314
ALYacBackdoor.MSIL.Quasar.gen
MalwarebytesTrojan.RCrypt.MSIL.Generic
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!e
SangforMalware
K7AntiVirusTrojan ( 0056081c1 )
BitDefenderTrojan.GenericKD.33275314
K7GWTrojan ( 0056081c1 )
Cybereasonmalicious.fe4d06
CyrenW32/MSIL_Kryptik.ADY.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojanSpy.MSIL.AZORULT.SMA
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDropper:Win32/InjectorGen.416d6f25
NANO-AntivirusTrojan.Win32.Kryptik.himoaf
Ad-AwareTrojan.GenericKD.33275314
SophosMal/Generic-S
ComodoMalware@#vqls25ize3hy
F-SecureHeuristic.HEUR/AGEN.1100758
ZillyaTrojan.Generic.Win32.1028134
TrendMicroTrojanSpy.MSIL.AZORULT.SMA
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeGeneric.mg.e181b306c65a5072
EmsisoftTrojan.GenericKD.33275314 (B)
IkarusTrojan.Agent
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1100758
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/InjectorGen.C!MSR
GridinsoftTrojan.Win32.Kryptik.oa
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.33275314
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Abnores.R327556
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=80)
CylanceUnsafe
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of MSIL/Kryptik.UGA
YandexTrojan.Kryptik!S7EsGk/ozqs
SentinelOneStatic AI – Malicious SFX
FortinetMSIL/GenKryptik.EDWB!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.cdf

How to remove Trojan:Win32/InjectorGen.C!MSR?

Trojan:Win32/InjectorGen.C!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment