Malware

Inject.22 malicious file

Malware Removal

The Inject.22 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Inject.22 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Inject.22?


File Info:

name: 20B270D2147956256946.mlw
path: /opt/CAPEv2/storage/binaries/cd49345fdc860cf7cb53971414685c56d59924a380f4d3ac98720421a4e7370e
crc32: F3541893
md5: 20b270d21479562569462c9e3ddc4e79
sha1: 57ac1a22b21997a010a9e134e966630023896792
sha256: cd49345fdc860cf7cb53971414685c56d59924a380f4d3ac98720421a4e7370e
sha512: ebbbde16a3a6f38b0f3c64745add6b2919df9148703c49dd2c6a61e67c9ff857fe7aabd23206f09cc0670ff0bbdab78804f87d17bfb9d7f78ef71f5742c6af2b
ssdeep: 6144:916G1TsR2rDlahi/66KgcLzTHItuu5ka+p:916q+ElagSzLzTotX5k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174340202C6562DD7D0682DF06A5977F929D07BAD826843AC81A7CF6C7E3C35CE520A36
sha3_384: 996eae3975c681af16902c0c49930bbc0a0ccc45dae66fdb8e9912502c8d6cb0d2caf06b328b8811f7bdc1cbb850c836
ep_bytes: b8180000006a006a006a406a006a0050
timestamp: 2004-08-10 18:20:20

Version Info:

CompanyName: G Data Software AG
FileVersion: 3.2.2
FileDescription: G Data AntiVirus
InternalName: GDATA
LegalCopyright: © G Data Software AG. All rights reserved.
OriginalFilename: GDATA.EXE
ProductName: G Data AntiVirus
ProductVersion: 3.2.2
Translation: 0x0409 0x04b0

Inject.22 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Buzus.kZ0o
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.20b270d214795625
McAfeeGeneric Dropper.aef
VIPREGen:Variant.Inject.22
SangforTrojan.Win32.Save.a
AlibabaTrojanSpy:Win32/Obfuscator.176fcd68
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Agent.PP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AXNO
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Inject.22
NANO-AntivirusTrojan.Win32.Inject.njeyx
MicroWorld-eScanGen:Variant.Inject.22
AvastFileRepMalware [Trj]
RisingMalware.Ursnif!8.E941 (TFE:2:XKNKSmtJb1O)
EmsisoftGen:Variant.Inject.22 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.PWS.Siggen.34612
ZillyaDropper.Injector.Win32.20119
McAfee-GW-EditionBehavesLike.Win32.Expiro.dc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Volisk
WebrootW32.Rogue.Gen
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan[Dropper]/Win32.Injector
XcitiumTrojWare.Win32.Kryptik.ADXI@4oyf3w
ArcabitTrojan.Inject.22
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Inject.22
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Inject.22
MAXmalware (ai score=99)
VBA32TrojanDropper.Injector
Cylanceunsafe
PandaGeneric Malware
TencentMalware.Win32.Gencirc.13b23673
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kazy.FDCC!tr
AVGFileRepMalware [Trj]
Cybereasonmalicious.214795
DeepInstinctMALICIOUS

How to remove Inject.22?

Inject.22 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment