Malware

How to remove “Win32/Injector.CRNL”?

Malware Removal

The Win32/Injector.CRNL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CRNL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Win32/Injector.CRNL?


File Info:

crc32: BFBB5AB8
md5: aa7160c57376d1f0a060d68fde6424dc
name: AA7160C57376D1F0A060D68FDE6424DC.mlw
sha1: 5a57ea64b353440b378fb5f2c15226cdf7e8c898
sha256: 1e334ec63bc3ad5ce7b4d905420975805a8da9fa42c6527625960feed97ab047
sha512: bd301fb65cd17fa603fd457bdbd5d73af24b5b9a89d201c5fff821ccf530b12b17b1f05c51a6ca432eb76ce08a64494dc8c7ab19f896c2a1d70f3b336b4ebdd8
ssdeep: 3072:lGlBadctVbVE8ydsen9adGLZL/8wK7wMXVac:GvtVmZZtK7wc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: ELOS
FileVersion: 7.03.0003
CompanyName: ELOS Rrack Security, Inc.
Comments: ELOS
ProductName: Fernsehfahndung3
ProductVersion: 7.03.0003
FileDescription: ELOS
OriginalFilename: ELOS.exe

Win32/Injector.CRNL also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.VBKryjetor.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.36755
ALYacGen:Heur.PonyStealer.jm1@n46uuDgb
CylanceUnsafe
ZillyaTrojan.VBKryjetor.Win32.1624
SangforTrojan.Win32.Injector.8
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Enchanim.a57116eb
K7GWTrojan ( 0055e3991 )
K7AntiVirusTrojan ( 0055e3991 )
ESET-NOD32a variant of Win32/Injector.CRNL
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Enchanim.pgt
BitDefenderGen:Heur.PonyStealer.jm1@n46uuDgb
NANO-AntivirusTrojan.Win32.VBKryjetor.eamarp
MicroWorld-eScanGen:Heur.PonyStealer.jm1@n46uuDgb
TencentWin32.Trojan.Enchanim.Lnxp
Ad-AwareGen:Heur.PonyStealer.jm1@n46uuDgb
SophosML/PE-A
ComodoMalware@#21975h29xlvuu
BitDefenderThetaGen:NN.ZevbaF.34266.jm1@a46uuDgb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.dul
FireEyeGeneric.mg.aa7160c57376d1f0
EmsisoftGen:Heur.PonyStealer.jm1@n46uuDgb (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Enchanim.d
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1124490
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1718417
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Heur.PonyStealer.jm1@n46uuDgb
McAfeeGeneric.dul
PandaTrj/GdSda.A
YandexTrojan.VBKryjetor!7EpvDq7fSRo
IkarusTrojan.Win32.Injector
FortinetW32/Injector.CRTG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.CRNL?

Win32/Injector.CRNL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment