Malware

MSIL/Injector.OBU (file analysis)

Malware Removal

The MSIL/Injector.OBU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.OBU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Mimics icon used for popular non-executable file format

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Injector.OBU?


File Info:

crc32: 953E9061
md5: 63dfd44b5c4a139edca180f9339874b8
name: 63DFD44B5C4A139EDCA180F9339874B8.mlw
sha1: c76ddbb5f5264612e55c1e832ceec34524fba785
sha256: 1dafb428b78a0eef7790c42561bae5cff251c1609984ac16ff1809cdeb9eda78
sha512: d4055510e5454b0a4ec197e1f555fbe8e505cfe91ead937bc51ec35c0aa828505435b29fbd43b76f320db91da9639a58fd6410e39c29c4f7714e4f3d1154db37
ssdeep: 12288:EBINvypWdUDI9zkFuUzxIzr3JCEONTc/0s9rzaoMxZE7RRRgNn:EBIVyhjjzKLJCElMKrm7MD8n
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright 1984-2011 Adobe Systems Incorporated and its licensors. All rights reserved.
FileVersion: 10.0.1.434
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Reader
ProductVersion: 10.0.1.434
FileDescription: Adobe Reader
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

MSIL/Injector.OBU also known as:

K7AntiVirusTrojan ( 004de62b1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.15595
CynetMalicious (score: 100)
ALYacIL:Trojan.MSILZilla.5040
CylanceUnsafe
SangforBackdoor.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/Injector.9685af35
K7GWTrojan ( 004de62b1 )
Cybereasonmalicious.b5c4a1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.OBU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.5040
NANO-AntivirusTrojan.Win32.Stealer.faflch
MicroWorld-eScanIL:Trojan.MSILZilla.5040
TencentMalware.Win32.Gencirc.114bc2b1
Ad-AwareIL:Trojan.MSILZilla.5040
SophosMal/Generic-R + Troj/MSIL-JHH
ComodoTrojWare.MSIL.Injector.DGY@6b3x79
BitDefenderThetaGen:NN.ZemsilF.34266.Nr3@aKaezbei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXIM-EH!63DFD44B5C4A
FireEyeGeneric.mg.63dfd44b5c4a139e
EmsisoftIL:Trojan.MSILZilla.5040 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.MSIL.Gen2
eGambitUnsafe.AI_Score_73%
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitIL:Trojan.MSILZilla.D13B0
GDataMSIL.Trojan.Injector.HJ
AhnLab-V3Malware/Gen.Generic.C1351494
McAfeeGenericRXIM-EH!63DFD44B5C4A
MAXmalware (ai score=99)
PandaTrj/GdSda.A
YandexTrojan.Injector!tR3gsfvFk7I
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Injector.OBU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Injector.OBU?

MSIL/Injector.OBU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment