Malware

Should I remove “MSIL/Injector.OKI”?

Malware Removal

The MSIL/Injector.OKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.OKI virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Injector.OKI?


File Info:

name: 9E2344C012B285DB3CA6.mlw
path: /opt/CAPEv2/storage/binaries/628c37375003fb800e0aee0df4597c2f6f3dae6f10f8af92692370114247af68
crc32: 66D2141D
md5: 9e2344c012b285db3ca6f48a9fbec6d7
sha1: db016343382a2fc1b06b02656ff5c1f707afd12f
sha256: 628c37375003fb800e0aee0df4597c2f6f3dae6f10f8af92692370114247af68
sha512: a08ac4c5b31e864607a2e16bca22aad2fc65d6fb86dfcf5a25f2cd6dca0aa7b51281b60a2154c33a2a22e38945aa10ee7108305b2feb365a11629927eb2dcd13
ssdeep: 768:qtSWJ2r5wfZZuKrMjGDlYyxcdF8e6IiP+YRzcwJQdpRJ:TrKfZZ3rAyxcf8UiP+FWgp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196434A492F2ED370D8ACA471F4264AF31224AEE4DE701FAB14E77E15F5B60228D1E60D
sha3_384: e00a85f9dc66eafbed638984b2da9d5e3f465c68e8afc0471248e7bc4a0f5e6327e7446a7a600ac1c536fbe0103cadd3
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-03-04 19:30:51

Version Info:

0: [No Data]

MSIL/Injector.OKI also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.53270
FireEyeGeneric.mg.9e2344c012b285db
McAfeeArtemis!9E2344C012B2
CylanceUnsafe
ZillyaTrojan.Injector.Win32.392603
Cybereasonmalicious.012b28
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.OKI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Barys.53270
NANO-AntivirusTrojan.Win32.BtcMine.eazwja
AvastWin32:Malware-gen
TencentMsil.Trojan.Crypt.Hupf
Ad-AwareGen:Variant.Barys.53270
EmsisoftGen:Variant.Barys.53270 (B)
ComodoMalware@#j61yqqkytbsf
DrWebTrojan.BtcMine.917
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.qh
SophosMal/Generic-S
IkarusTrojan.MSIL.Injector
GDataGen:Variant.Barys.53270
JiangminTrojan.Generic.rcqi
eGambitUnsafe.AI_Score_98%
AviraHEUR/AGEN.1127775
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Barys.DD016
MicrosoftTrojan:MSIL/BitcoinMiner.A
CynetMalicious (score: 99)
BitDefenderThetaGen:NN.ZemsilF.34062.dmW@aSrBxbd
ALYacGen:Variant.Barys.53270
YandexTrojan.Agent!MVEaKmtKTck
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.FAJ!tr
WebrootTrojan.Spy.Omaneat
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove MSIL/Injector.OKI?

MSIL/Injector.OKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment