Malware

MSIL/Injector.ZO (file analysis)

Malware Removal

The MSIL/Injector.ZO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Injector.ZO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients

How to determine MSIL/Injector.ZO?


File Info:

name: 9EF092AA08AF6E3B1F66.mlw
path: /opt/CAPEv2/storage/binaries/489851792e8683c0440f81f8dfc012b466449cae35e26d7db1991d55a48d735a
crc32: 35F639E1
md5: 9ef092aa08af6e3b1f66b721e80b6dfd
sha1: ca25f06aedccca8af8e20de616bd92fe0a83bd2e
sha256: 489851792e8683c0440f81f8dfc012b466449cae35e26d7db1991d55a48d735a
sha512: 0894d8c3340a0d59245e83b1eef309818006411318ac80f0280d57dabdb35fbedb0eff0d715837ced6995f2bb6a0c2b234e6d40572ecbf301bbc54855b7e8b04
ssdeep: 3072:FUM7R/2bhQUUupoCri4/4LFAIEEHC6hUERBnKODpUbmMa+YqqQER2SD7TuCB:57RO+upr2wdnERhBRB1UbLkqAR2SD7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F32487543AFEA15CF1737FB16EE8B5D98AAFF7721A06B0BD104103075A21E41CEA5632
sha3_384: a30e51b519b2f49f3638c53f70465849c1a0de2824c1e3514658d06f2cb124de907cd4c8189c8e21495eb95171aca1e2
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-04-09 08:51:56

Version Info:

Translation: 0x0000 0x04b0
Comments: BCzFcjqUhgwB
CompanyName: EuUjcMtwRtxMI
FileDescription: LidHJpKPXNs
FileVersion: 2.2.2.3
InternalName: Server.exe
LegalCopyright: qFeeFOaDWCZrRr
LegalTrademarks: DwPyVFPVRduJRSb
OriginalFilename: Server.exe
ProductName: ytXZGMfndJ
ProductVersion: 2.2.2.3
Assembly Version: 8.9.2.5

MSIL/Injector.ZO also known as:

LionicTrojan.Win32.Generic.lVvz
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.Basic.3.Gen
FireEyeGeneric.mg.9ef092aa08af6e3b
ALYacTrojan.MSIL.Basic.3.Gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
AlibabaTrojan:MSIL/Injector.468023a8
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.ZO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1020308
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.MSIL.Basic.3.Gen
NANO-AntivirusTrojan.Win32.AVKill.olvhx
AvastWin32:Malware-gen
TencentWin32.Init.QQRob.ciey
SophosML/PE-A + Mal/Generic-L
ComodoMalware@#3rgrf4u291eyw
DrWebTrojan.AVKill.3599
ZillyaTrojan.Agent.Win32.239215
TrendMicroTROJ_SPNR.30BD13
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.MSIL.Basic.3.Gen (B)
IkarusVirus.Win32.VBInject
JiangminTrojan/PSW.MSIL.aez
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.MSIL.Basic.3.Gen
CynetMalicious (score: 99)
McAfeeArtemis!9EF092AA08AF
MAXmalware (ai score=88)
VBA32TrojanPSW.MSIL.Agent
TrendMicro-HouseCallTROJ_SPNR.30BD13
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:rll0i14m0sPRzvJdeyZUgg)
YandexTrojan.PWS.Agent!IGbeBVWreeg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.HSF!tr
BitDefenderThetaGen:NN.ZemsilF.34182.nm0@a4ho3tk
AVGWin32:Malware-gen
Cybereasonmalicious.a08af6
PandaGeneric Malware

How to remove MSIL/Injector.ZO?

MSIL/Injector.ZO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment