Malware

Should I remove “MSIL/Injector.BOP”?

Malware Removal

The MSIL/Injector.BOP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.BOP virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine MSIL/Injector.BOP?


File Info:

crc32: 65A8FF01
md5: 514b4ecae82906ec28a417792e0a5ab3
name: 514B4ECAE82906EC28A417792E0A5AB3.mlw
sha1: 0bcb89679241e9474fca89cd35b42b5bcd079961
sha256: 8d28776c97231b2fe381fd088341d133d63a9f6a57c51066c3e46b8c34ceffdd
sha512: 01c1cac494671b0ab16225b616e14fc326e1da88ac6c68b7f438a4ac187cd610602b896562b6d38c896e02c38b34e6db1f6b532b85fd874b94270c02a731cd61
ssdeep: 1536:oHa06/1AapvYvEc1Ci8kz26uLGoaptWXz5tA/IcJtmZU68W:+ezRYvEc1H8YuLv4WXjAPQZUbW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright 2012 Google Inc. All rights reserved.
InternalName: chrome_exe
CompanyShortName: Google
FileVersion: 28.0.1500.71
CompanyName: Google Inc.
ProductShortName: Chrome
ProductName: Google Chrome
LastChange: 209842
ProductVersion: 28.0.1500.71
FileDescription: Google Chrome
OriginalFilename: chrome.exe
Official Build: 1
Translation: 0x0409 0x04b0

MSIL/Injector.BOP also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Pontob.1
ALYacGen:Variant.Barys.2440
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.9541
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.73cdd47c
K7GWTrojan ( 004ec0971 )
K7AntiVirusTrojan ( 004ec0971 )
CyrenW32/Trojan.VDED-4726
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BOP
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.brea
BitDefenderGen:Variant.Barys.2440
NANO-AntivirusTrojan.Win32.Blocker.bxxgcd
MicroWorld-eScanGen:Variant.Barys.2440
TencentWin32.Trojan.Blocker.Ssqt
Ad-AwareGen:Variant.Barys.2440
SophosMal/Generic-S
ComodoMalware@#oiw0viwt6nb0
BitDefenderThetaGen:NN.ZemsilF.34678.fm0@aeHj7i
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeGeneric.mg.514b4ecae82906ec
EmsisoftGen:Variant.Barys.2440 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.orm
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1102043
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sisron
ArcabitTrojan.Barys.D988
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Barys.2440
AhnLab-V3Win-Trojan/MSILKrypt02.Exp
McAfeeArtemis!514B4ECAE829
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesTrojan.PasswordStealer.MSIL
PandaGeneric Malware
RisingTrojan.FakeChrome!1.9C7B (CLOUD)
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.BREA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwMAEpsA

How to remove MSIL/Injector.BOP?

MSIL/Injector.BOP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment