Threat Database Trojans Trojan.MSIL.Inject.U

Trojan.MSIL.Inject.U

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,491
Threat Level: 80 % (High)
Infected Computers: 135
First Seen: August 27, 2021
Last Seen: July 26, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Inject.U on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system. It's crucial to approach this situation with a clear understanding of the risks and the necessary actions to mitigate them.

What Is Trojan.MSIL.Inject.U?

Trojan.MSIL.Inject.U is identified as a Trojan-type threat. Trojans are malicious programs that can cause significant harm to computer systems. They are designed to appear as legitimate software but are actually intended to breach the security of a system once installed. The name "Trojan.MSIL.Inject.U" suggests it may involve injection techniques, potentially allowing it to embed itself into other processes or applications, making it harder to detect and remove.

How Trojan.MSIL.Inject.U Operates

The operational mechanisms of Trojan.MSIL.Inject.U, like many Trojans, likely involve exploiting vulnerabilities in the system or application software to gain unauthorized access. Once inside, it can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing backdoor access to the attackers. The specifics of how it operates can vary, but the end goal is typically to compromise the system's security and integrity for malicious purposes.

Symptoms of Infection

Systems infected with Trojan.MSIL.Inject.U may exhibit a range of symptoms, although some infections can be asymptomatic, making them particularly dangerous. Common signs include unexpected system crashes, significant slowdowns in performance, unusual network activity, or the appearance of unwanted programs or toolbars in your web browser. Additionally, you might notice that your antivirus software is disabled or that certain system settings have been altered without your consent.

How to Remove Trojan.MSIL.Inject.U

Removing Trojan.MSIL.Inject.U requires a careful and systematic approach to ensure that all components of the malware are eliminated from your system. The following steps are recommended:

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve detection and removal capabilities.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings that the Trojan may have installed.
  5. Reboot your computer and perform another full scan to ensure that no remnants of the malware remain. This step is crucial as some malware can reinstall itself if not completely removed.

Conclusion

The removal of Trojan.MSIL.Inject.U from your system is a critical step in restoring your computer's security and performance. It's essential to be proactive and diligent in maintaining your system's security through regular updates, using reputable antivirus software, and practicing safe computing habits. Remember, prevention is key, but when infections do occur, acting swiftly and following a structured removal process can help mitigate the damage and prevent future occurrences.

Analysis Report

General information

Family Name: Trojan.MSIL.Inject.U
Signature status: No Signature

Known Samples

MD5: c1c51ec5022b2b9d197fdd4d9f60fd0c
SHA1: 941478d538d13a1036560989932241d540889002
SHA256: 43D1A491266E77CFFEAC4C5CE0F675E33659223F72BA66039AC712FB31E4D8DB
File Size: 1.56 MB, 1560064 bytes
MD5: a2c95c1fb991254b58a5105dfa2506c7
SHA1: 75dbb38e0e6770ee6659ad3fc14a838efa2fe6be
SHA256: BB184DC5F2E23822BE808AFB11BEB80DF96F455B26C0165F80FEF84B01349C29
File Size: 1.56 MB, 1560576 bytes
MD5: 2188ae0ff06f600fe96c5e085d44c1dc
SHA1: 9ca1622efe9c5432d902a8e9a07aa3d766a80b12
SHA256: 117F2FAF5068A299E33AFDF18A64A9775D76EB340D1FF9B6B4CA479F493BE2E2
File Size: 583.68 KB, 583680 bytes
MD5: 1487982d443175be1d300fcd804ea4da
SHA1: 3b60880b2c6608270539d1b80155714a7f732641
SHA256: 04F3A3D349B17EFC4A1122EF1AC9D83FE15F59798BC8358BC2258E4E904105AC
File Size: 691.20 KB, 691200 bytes
MD5: f5e9d4f35c0c4e01576cca18c49efe43
SHA1: 7dfb4a5fd64d1a647b711cd0659ddcdc1b81b221
SHA256: ADD5506E0C70E5F479208F78628A4023843BA2C9AC705259858950495D6B94EE
File Size: 872.45 KB, 872448 bytes
Show More
MD5: 3b6776bb93bd664707288d873a66fe2d
SHA1: 3e4374beb574cf1c6f9adb50d1fbc74d021d6402
SHA256: 695C6ED668476E0E3F615968549250D115C9C8C29AFCD8D66E655F193FDDD09A
File Size: 3.99 MB, 3991271 bytes
MD5: d1c3c8ec01338663cfa8164b68f31912
SHA1: d1d4ee38301ea74f222b54131e9cdba4ee7dd1dc
SHA256: EC3EF34718D78A4A0247DF99B47084D22425F909596C24E0262FB90B1767A637
File Size: 31.23 KB, 31232 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 3.0.0.1
  • 2.8.0.0
  • 2.2.0.1
  • 2.1.0.19
  • 1.1.1.0
  • 0.6.0.0
Comments This installation was built with Inno Setup.
Company Name
  • DAII, S.L.
  • Koyote Soft
  • Koyote Soft
  • Scanrem
  • Service System
File Description
  • Batman:Ackham City日本語テキスト抽出・反映
  • DSS_BOX
  • EstadisticasNET
  • FreeVideoConverter
  • Free Video Converter Setup
  • Scanrem
File Version
  • 3.0.0.1
  • 2.8.0.0
  • 2.8.0.0
  • 2.2.0.1
  • 2.1.0.19
  • 1.1.1.0
  • 0.6.0.0
Internal Name
  • BAC_JpTool.exe
  • DSS_BOX.exe
  • EstadisticasNET.exe
  • FreeVideoConverter.exe
  • Scanrem.exe
Legal Copyright
  • Copyright © 2010
  • Copyright © 2011
  • Copyright © DAII, S.L. 2011
  • Copyright © Scanrem 2013
  • Copyright © Service System 2014
  • Copyright © Service System 2015
  • Koyote Soft
Legal Trademarks All Rights Reserved
Original Filename
  • BAC_JpTool.exe
  • DSS_BOX.exe
  • EstadisticasNET.exe
  • FreeVideoConverter.exe
  • Scanrem.exe
Product Name
  • Batman:Ackham City日本語テキスト抽出・反映
  • DSS_BOX
  • EstadisticasNET
  • FreeVideoConverter
  • Free Video Converter
  • Scanrem
Product Version
  • 3.0.0.1
  • 2.8.0.0
  • 2.8.0.0
  • 2.2.0.1
  • 2.1.0.19
  • 1.1.1.0
  • 0.6.0.0

File Traits

  • .NET
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 52
Potentially Malicious Blocks: 3
Whitelisted Blocks: 35
Unknown Blocks: 14

Visual Map

0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.blf Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-n0ckc.tmp\3e4374beb574cf1c6f9adb50d1fbc74d021d6402_0003991271.tmp Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k4 �v ��T�����&�-(�(X�*J1�1HO@V�A��G�IH[uH�pU_*_�zb"hh�rk�qq�Xvy�w�n{b��P��jI����������6������.������*� [�m�Ù��'NƾB�]�����=��$�Ac�8წ���&M��>G�5O�=�S/�.S RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱穓隞̃耀꧌љ̶ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k�8���8 �6 �v �Z xy ��T���������5����Bx!wz#�#��$kF%:�&� &�-(�(X�)E*J*9+�[,��/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�F?G�IH[uH�pH��I��J��K��N$R20U_*V �X�_�z`b.`�2b"h RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 馐ʊ耀Ś#洎ʫጉ嵑즶픋˹耀뫹躧隞̃紁耀꧌Ǝౌ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m��jg �� �v xy ��T������%������Bx�<#�#��&� &�-(�(X�(�)�`*J*9*�",��-!R1�1HO1�D5,]9ߔ@V�A��G�IH[uH�pJ��N$N�R20U_*X�.X�`�2b"hc�wc�zh�ri��j�bk`k�ql(�lR o�q�XrnJ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱嬻馐ʊ耀Ś洎ʫ艄콘˕픋˹耀뫹躧隞̃ᔁ耀꧌ʅڄ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Keyboard Access
  • GetKeyState

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 816
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 848
"C:\Users\Ooouztmr\AppData\Local\Temp\is-N0CKC.tmp\3e4374beb574cf1c6f9adb50d1fbc74d021d6402_0003991271.tmp" /SL5="$19003A,3651430,54272,c:\users\user\downloads\3e4374beb574cf1c6f9adb50d1fbc74d021d6402_0003991271"