Malware

Troj/Inject-INM removal instruction

Malware Removal

The Troj/Inject-INM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Inject-INM virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Troj/Inject-INM?


File Info:

name: 0FE0844BED66BB922FE1.mlw
path: /opt/CAPEv2/storage/binaries/0113c2cbf746a3395cc7da07ef9670fd221742d71d9dffe1287f484c4b78e81d
crc32: 9CDA92C4
md5: 0fe0844bed66bb922fe17491ed6c48c0
sha1: bbfe5ceee2e9269dffbb8c982e03eb82b23d20bc
sha256: 0113c2cbf746a3395cc7da07ef9670fd221742d71d9dffe1287f484c4b78e81d
sha512: 1e6eca2eec8e3f57c23f7a59ae472665f46007f57da30d36c5d9e66673eb4d6e6d5573fd835e01f45fcd431fbc50169df64979e691295c5efb9eaa2fbbf8f988
ssdeep: 24576:L++ZwJfwCI8Ddfs/kMUftLGZ98FlE6wI+gfnlRIfaE3JRdP:L1/kjtPlERDGnlRANRdP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A757C23E691C0F1D11100B11AF5573DAA78BB774E359BA3EB92DEB45D212E2CE1720E
sha3_384: 3c0b90b1cfd9f630f6da3f6cf4081c8594bfb570633767d7a964e621f695e382812d9ef87f547d939b9826b2b7c6f180
ep_bytes: 558bec6aff6880b34500689023450064
timestamp: 2016-08-17 08:34:04

Version Info:

FileVersion: 5.6.1.1
FileDescription:
ProductName:
ProductVersion: 5.6.1.1
CompanyName:
LegalCopyright:
Comments: 本程序使用易语言编写(http://www.dywt.com.cn)
Translation: 0x0804 0x04b0

Troj/Inject-INM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94519
FireEyeTrojan.GenericKDZ.94519
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXDM-NN!0FE0844BED66
Cylanceunsafe
ZillyaTrojan.GenericKD.Win32.147726
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusTrojan ( 005328801 )
AlibabaMalware:Win32/km_2418d.None
K7GWTrojan ( 005328801 )
Cybereasonmalicious.ee2e92
VirITTrojan.Win32.Dnldr23.CPXA
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKDZ.94519
AvastWin32:Malware-gen
TencentAdware.Win32.Hebchengjiu.16000480
EmsisoftTrojan.GenericKDZ.94519 (B)
DrWebTrojan.DownLoader23.45890
VIPRETrojan.GenericKDZ.94519
TrendMicroAdware.Win32.Hebchengjiu.SM
SophosTroj/Inject-INM
IkarusTrojan.Win32.Tonmye
GDataWin32.Trojan.PSE.XQU6XR
JiangminAdWare.Generic.cpln
WebrootW32.Trojan.Gen
GoogleDetected
Antiy-AVLTrojan/Win32.SGeneric
XcitiumApplication.Win32.AdWare.Hebchengjiu.B@72arj8
ArcabitTrojan.Generic.D17137
MicrosoftTrojan:Win32/Upatre
VaristW32/S-fdbd06de!Eldorado
AhnLab-V3Dropper/Win.Injector.R451014
ALYacTrojan.GenericKDZ.94519
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallAdware.Win32.Hebchengjiu.SM
RisingDownloader.Generic!8.141 (TFE:5:7LXjXuuHuaJ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Redcap
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Troj/Inject-INM?

Troj/Inject-INM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment