Malware

Mal/Inject-H removal tips

Malware Removal

The Mal/Inject-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Inject-H virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Inject-H?


File Info:

crc32: D6A738EF
md5: 70e07f4c92d23b3ab7fd3e10e02ad1d3
name: 70E07F4C92D23B3AB7FD3E10E02AD1D3.mlw
sha1: 1a4118c10aaddaef7c7f8c6515a195b122b06e6c
sha256: 729431e0cd28d6daee75c8f7940280a647c05011895de4c33df290aa3104de70
sha512: d45386f11fd955da3b929dc3bfea9ed85bf3d3f64eca6d1b3760784596181164a22b967b28724df045305e8b50a48f1cec98ec99e5fbbd680a52e43910522dc9
ssdeep: 768:AvrkeY9k/QCYH19iS9cxcOIjeV9ybIPybIjybImybIeybI6ybIg:ANnIDexcOIjIJ14AEg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
LegalCopyright: Badoo. Entra. Destaca. xa1Consigue fans! /* inline source: https://pd2us.badoocdn.com/i/v2/-/-/js/hon_v3/assets/css/ltr/-/css/hotornot_v2/base.critical.cc50e2aa878cdd15ee8d.css */ @-webkit-keyframes show0%opacity:0toopacity:1@keyframes show0%opacity:0toopacity:1@-webkit-keyframes hide0%opacity:1toopacity:0@keyframes hide0%opacity:1toopacity:0.loggerposition:relative;overflow:auto;width:100%;max-height:90vh;border:1px solid #fd7f7e;background:#fff.logger.is-collapsedposition:fixed;z-index:10000;overflow:hidden;width:50px;height:50px.logger.is-collapsed::afterposition:absolute;top:0;left:0;width:100%;height:100%;content:'!';background:#fd7f7e;color:#fff;text-align:center;font-size:30px;line-height:48pxa,abbr,acronym,address,applet,article,aside,b,big,blockquote,body,caption,center,cite,c
InternalName: stub
FileVersion: 4467.777.1113
CompanyName: Badoo. Entra. Destaca. xa1Consigue fans! /* inline source: https://pd2us.badoocdn.com/i/v2/-/-/js/hon_v3/assets/css/ltr/-/css/hotornot_v2/base.critical.cc50e2aa878cdd15ee8d.css */ @-webkit-keyframes show0%opacity:0toopacity:1@keyframes show0%opacity:0toopacity:1@-webkit-keyframes hide0%opacity:1toopacity:0@keyframes hide0%opacity:1toopacity:0.loggerposition:relative;overflow:auto;width:100%;max-height:90vh;border:1px solid #fd7f7e;background:#fff.logger.is-collapsedposition:fixed;z-index:10000;overflow:hidden;width:50px;height:50px.logger.is-collapsed::afterposition:absolute;top:0;left:0;width:100%;height:100%;content:'!';background:#fd7f7e;color:#fff;text-align:center;font-size:30px;line-height:48pxa,abbr,acronym,address,applet,article,aside,b,big,blockquote,body,caption,center,cite,code
LegalTrademarks: Badoo. Entra. Destaca. xa1Consigue fans! /* inline source: https://pd2us.badoocdn.com/i/v2/-/-/js/hon_v3/assets/css/ltr/-/css/hotornot_v2/base.critical.cc50e2aa878cdd15ee8d.css */ @-webkit-keyframes show0%opacity:0toopacity:1@keyframes show0%opacity:0toopacity:1@-webkit-keyframes hide0%opacity:1toopacity:0@keyframes hide0%opacity:1toopacity:0.loggerposition:relative;overflow:auto;width:100%;max-height:90vh;border:1px solid #fd7f7e;background:#fff.logger.is-collapsedposition:fixed;z-index:10000;overflow:hidden;width:50px;height:50px.logger.is-collapsed::afterposition:absolute;top:0;left:0;width:100%;height:100%;content:'!';background:#fd7f7e;color:#fff;text-align:center;font-size:30px;line-height:48pxa,abbr,acronym,address,applet,article,aside,b,big,blockquote,body,caption,center,cite,
Comments: Badoo. Entra. Destaca. xa1Consigue fans! /* inline source: https://pd2us.badoocdn.com/i/v2/-/-/js/hon_v3/assets/css/ltr/-/css/hotornot_v2/base.critical.cc50e2aa878cdd15ee8d.css */ @-webkit-keyframes show0%opacity:0toopacity:1@keyframes show0%opacity:0toopacity:1@-webkit-keyframes hide0%opacity:1toopacity:0@keyframes hide0%opacity:1toopacity:0.loggerposition:relative;overflow:auto;width:100%;max-height:90vh;border:1px solid #fd7f7e;background:#fff.logger.is-collapsedposition:fixed;z-index:10000;overflow:hidden;width:50px;height:50px.logger.is-collapsed::afterposition:absolute;top:0;left:0;width:100%;height:100%;content:'!';background:#fd7f7e;color:#fff;text-align:center;font-size:30px;line-height:48pxa,abbr,acronym,address,applet,article,aside,b,big,blockquote,body,caption,center,cite,code,dd
ProductName: Badoo. Entra. Destaca. xa1Consigue fans! /* inline source: https://pd2us.badoocdn.com/i/v2/-/-/js/hon_v3/assets/css/ltr/-/css/hotornot_v2/base.critical.cc50e2aa878cdd15ee8d.css */ @-webkit-keyframes show0%opacity:0toopacity:1@keyframes show0%opacity:0toopacity:1@-webkit-keyframes hide0%opacity:1toopacity:0@keyframes hide0%opacity:1toopacity:0.loggerposition:relative;overflow:auto;width:100%;max-height:90vh;border:1px solid #fd7f7e;background:#fff.logger.is-collapsedposition:fixed;z-index:10000;overflow:hidden;width:50px;height:50px.logger.is-collapsed::afterposition:absolute;top:0;left:0;width:100%;height:100%;content:'!';background:#fd7f7e;color:#fff;text-align:center;font-size:30px;line-height:48pxa,abbr,acronym,address,applet,article,aside,b,big,blockquote,body,caption,center,cite,code
ProductVersion: 4467.777.1113
FileDescription: Badoo. Entra. Destaca. xa1Consigue fans! /* inline source: https://pd2us.badoocdn.com/i/v2/-/-/js/hon_v3/assets/css/ltr/-/css/hotornot_v2/base.critical.cc50e2aa878cdd15ee8d.css */ @-webkit-keyframes show0%opacity:0toopacity:1@keyframes show0%opacity:0toopacity:1@-webkit-keyframes hide0%opacity:1toopacity:0@keyframes hide0%opacity:1toopacity:0.loggerposition:relative;overflow:auto;width:100%;max-height:90vh;border:1px solid #fd7f7e;background:#fff.logger.is-collapsedposition:fixed;z-index:10000;overflow:hidden;width:50px;height:50px.logger.is-collapsed::afterposition:absolute;top:0;left:0;width:100%;height:100%;content:'!';background:#fd7f7e;color:#fff;text-align:center;font-size:30px;line-height:48pxa,abbr,acronym,address,applet,article,aside,b,big,blockquote,body,caption,center,cite,
OriginalFilename: stub.exe

Mal/Inject-H also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Barys.5417
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaVirTool:Win32/Vbinder.10c0481c
K7GWTrojan ( 004e58da1 )
Cybereasonmalicious.c92d23
CyrenW32/VBCrypt.A!Generic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ZC
APEXMalicious
AvastWin32:VB-LJN [Drp]
ClamAVWin.Trojan.Generic-8439775-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.5417
MicroWorld-eScanGen:Variant.Barys.5417
TencentWin32.Trojan.Dropper.Ahye
Ad-AwareGen:Variant.Barys.5417
SophosMal/Inject-H
BitDefenderThetaAI:Packer.B4E207E81E
VIPREVirTool.Win32.Vbinder.gen.g (v)
McAfee-GW-EditionBackDoor-DZP.b
FireEyeGeneric.mg.70e07f4c92d23b3a
EmsisoftGen:Variant.Barys.5417 (B)
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftVirTool:Win32/Vbinder.gen!G
ArcabitTrojan.Barys.D1529
GDataGen:Variant.Barys.5417
AhnLab-V3Dropper/Win32.Typic.C118283
McAfeeBackDoor-DZP.b
MAXmalware (ai score=83)
VBA32Malware-Cryptor.VB.gen.1
MalwarebytesTrojan.MassLogger
PandaGeneric Malware
RisingHackTool.Vbinder!8.4E7 (CLOUD)
YandexTrojan.GenAsa!FslvCQTkWFE
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-LJN [Drp]

How to remove Mal/Inject-H?

Mal/Inject-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment