Malware

About “VirTool:MSIL/CryptInject” infection

Malware Removal

The VirTool:MSIL/CryptInject is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/CryptInject virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VirTool:MSIL/CryptInject?


File Info:

crc32: A6E1EC84
md5: c6889c70ce098c71d49f6297266c3c3f
name: C6889C70CE098C71D49F6297266C3C3F.mlw
sha1: 7fd05e645a647987c6f2f70015d86abd60dd1796
sha256: a509e1c9624f9d3bbe63f071c8e53a40f05132bbeb42a1048cf57a6c743e7a8b
sha512: 1f547b5e30ffb2a2cadfd77ce15424bbd4643d585fd7adcf49684bba7673ead824856f679713254d06283519e94a2f9ccdffaf308d140d6f508b600e4fe65999
ssdeep: 49152:j/dvDllxzT2G+J8mMrm1RF4cUwSN24VHgOGf78Zbn+1qkq6h8ZbnRUH:pvDllxZmMrm1RF4vww2sHgOW1qf63
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 2001
InternalName: Microsoft New Phonetic IME user define phrase tool
FileVersion: 5.2.2801
CompanyName: Microsoft Corporation
Comments: Unicode IME
ProductName: New Phonetic
ProductVersion: 5.2.2801
FileDescription: Microsoft New Phonetic IME 2002a user define phrase tool
OriginalFilename: TINTLPHR.EXE
Translation: 0x0404 0x03b6

VirTool:MSIL/CryptInject also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.40956
FireEyeGeneric.mg.c6889c70ce098c71
ALYacTrojan.GenericKD.33681992
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Fugrafa.40956
CyrenW32/Agent.BUU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
AlibabaWorm:Win32/Bloored.49d6b478
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareTrojan.GenericKD.33681992
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1137911
McAfee-GW-EditionBehavesLike.Win32.Trojan.rm
EmsisoftGen:Variant.Fugrafa.40956 (B)
IkarusWorm.Win32.Bloored
AviraHEUR/AGEN.1137911
MAXmalware (ai score=80)
MicrosoftVirTool:MSIL/CryptInject
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Fugrafa.D9FFC
GDataTrojan.GenericKD.33681992
CynetMalicious (score: 100)
McAfeeArtemis!C6889C70CE09
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Bloored.FD1F!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.b3b

How to remove VirTool:MSIL/CryptInject?

VirTool:MSIL/CryptInject removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment