Malware

Win32/Injector.DMYI information

Malware Removal

The Win32/Injector.DMYI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DMYI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.DMYI?


File Info:

crc32: C1C98351
md5: 0fb1384e8e34d6c3c9e6c23d35ff5359
name: 0FB1384E8E34D6C3C9E6C23D35FF5359.mlw
sha1: d750faa42b496c1cce5cee0a2879efdc2badc456
sha256: 68f15600e889278aada0762a0fb84c11501bf3913380686aac74e6b3d4443368
sha512: 7582d09b466ac81856eec23b201d9e24e77fc0132b3a978dbaf7fcc52d227cc7a4ac6df65933a9c5a62b82a7885c843ba83325fbe3350f5d50d862b8cf4230d6
ssdeep: 3072:S1JhA4DbgcFRETC3aji8ObxqNsgRCALASOYE8:MPA4DbgcFl3aj6NWRN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Reo QG
InternalName: Maliki
FileVersion: 4.06.0006
CompanyName: Asus
ProductName: CA gware
ProductVersion: 4.06.0006
OriginalFilename: Maliki.exe

Win32/Injector.DMYI also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.wm0@cSzdBlgi
FireEyeGeneric.mg.0fb1384e8e34d6c3
ALYacGen:Heur.PonyStealer.wm0@cSzdBlgi
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0050971a1 )
BitDefenderGen:Heur.PonyStealer.wm0@cSzdBlgi
K7GWTrojan ( 0050971a1 )
Cybereasonmalicious.e8e34d
TrendMicroTSPY_HPFAREIT.SME
CyrenW32/VBInject.HO3.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
ClamAVWin.Packed.Ponystealer-9791237-0
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Heur.PonyStealer.wm0@cSzdBlgi
SophosMal/FareitVB-M
F-SecureHeuristic.HEUR/AGEN.1126331
DrWebTrojan.PWS.Siggen2.59479
ZillyaTrojan.VBKrypt.Win32.266911
InvinceaML/PE-A + Mal/FareitVB-M
McAfee-GW-EditionPacked-KR!0FB1384E8E34
EmsisoftGen:Heur.PonyStealer.wm0@cSzdBlgi (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126331
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.VBKrypt
MicrosoftTrojan:Win32/Wacatac.D6!ml
ArcabitTrojan.PonyStealer.E48CBC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.PonyStealer.wm0@cSzdBlgi
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeePacked-KR!0FB1384E8E34
VBA32Trojan.Packed
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DMYI
TrendMicro-HouseCallTSPY_HPFAREIT.SME
RisingMalware.Undefined!8.C (TFE:4:N1aXQHKke9)
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.DOLW!tr
BitDefenderThetaGen:NN.ZevbaF.34634.wm0@aSzdBlgi
AVGWin32:InjectorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.4AFB.Malware.Gen

How to remove Win32/Injector.DMYI?

Win32/Injector.DMYI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment