Malware

MSIL/Injector.SRO (file analysis)

Malware Removal

The MSIL/Injector.SRO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.SRO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial language used in binary resources: Greek
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Exhibits behavior characteristic of iSpy Keylogger
  • Network activity detected but not expressed in API logs

How to determine MSIL/Injector.SRO?


File Info:

crc32: 88B40F19
md5: 4aaa185aaf2083cfff070c0043571c86
name: 4AAA185AAF2083CFFF070C0043571C86.mlw
sha1: e1d020ab729be571af261d5ed0cee6dded41bf86
sha256: dd2285374e42063ba99ca44eed4215007f46b4d7f220aa26922816c36712883d
sha512: 2a828175ec0958c00438d97bb7156d43a4763b30eef6428e58abdc773f166d2c7bb7cd0b89a20859e8eed841bfa6cb12efdd587be046e003ab06e9f576e9b9eb
ssdeep: 12288:1rV+z8BiwHSu2s8+K01GKas7WOUuoEjrMpHU1Tw4lI6wbJ0:1roz8swH2QGrsqOUPEj+UFIJ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2017
Assembly Version: 15.52.154.11
InternalName: BkoHskh.exe
FileVersion: 15.52.154.11
CompanyName:
Comments:
ProductName: BkoHskh
ProductVersion: 15.52.154.11
FileDescription: WRP Integrity API
OriginalFilename: BkoHskh.exe
Translation: 0x0408 0x04b0

MSIL/Injector.SRO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.40020
FireEyeGeneric.mg.4aaa185aaf2083cf
McAfeePacked-OZ!4AAA185AAF20
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005138a31 )
BitDefenderTrojan.GenericKDZ.40020
K7GWTrojan ( 005138a31 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34804.Im0@aWyGmufG
CyrenW32/Trojan.SW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Generic
AlibabaTrojan:Win32/csharp.ali2000008
NANO-AntivirusTrojan.Win32.Stealer.erqadb
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKDZ.40020
SophosMal/Generic-S + Mal/MSIL-SZ
F-SecureHeuristic.HEUR/AGEN.1131977
DrWebTrojan.PWS.Stealer.17779
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftTrojan.Agent (A)
IkarusTrojan.Inject
AviraHEUR/AGEN.1131977
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanSpy:MSIL/Golroted.A
ArcabitTrojan.Generic.D9C54
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataTrojan.GenericKDZ.40020
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.ZBot.C683467
ALYacTrojan.GenericKDZ.40020
MAXmalware (ai score=100)
MalwarebytesSpyware.LokiBot
PandaTrj/Agent.AAF
ESET-NOD32a variant of MSIL/Injector.SRO
YandexTrojan.Agent!QKkMp2aCvys
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Injector.SRY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.7c5

How to remove MSIL/Injector.SRO?

MSIL/Injector.SRO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment