Malware

Win32/Injector.IBX removal instruction

Malware Removal

The Win32/Injector.IBX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.IBX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Injector.IBX?


File Info:

name: 00E515243F5AAB04F4ED.mlw
path: /opt/CAPEv2/storage/binaries/7cd6e87fbb143b5c5d859e5635a37e4f54794989170d43fdc5007f540285b458
crc32: C5C6A6E4
md5: 00e515243f5aab04f4ed00c30827b261
sha1: 673f2c326673605e882b113dde3135244e3becc9
sha256: 7cd6e87fbb143b5c5d859e5635a37e4f54794989170d43fdc5007f540285b458
sha512: c7751ac1786285330bd79b58d6bbccf572c01300fc5db6f3b94dfef1c80247ee53d2c854d480d7336240375c49810d8f61185b45a90716aa137f39b3f2769d62
ssdeep: 1536:RrWMFUxCnOoIGdrPlPQXeDCK+t+YGRRJF4enfQ4qETRJbGErVVH:QZxCjIG5RsgRLfQ4qIRpv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118C3FA366BA9F02EE3BD81749B585A96A067653A29108CFE40F7020DDB776435DF032F
sha3_384: 35203acf6bf41e36e1e778d0fe82ab8f6fc5cc3eca4ae8a0fa0165f0dc7b9bbbecb601a2db540e23b4bee63b1349fb88
ep_bytes: 6850174000e8eeffffff000000000000
timestamp: 2011-07-24 18:57:38

Version Info:

Translation: 0x0409 0x04b0
Comments: Oxnard Loire Nebraska Exxon Montgomery
CompanyName: Halstead Carthage Jacobus Missouri
FileDescription: Andrew Marion Huxtable Bloch
LegalCopyright: Muir Oakley Stegosaurus Caruso Purcell
ProductName: Fiji Textron
FileVersion: 4.07.0002
ProductVersion: 4.07.0002
InternalName: nianr
OriginalFilename: nianr.exe

Win32/Injector.IBX also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Timer.j!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.49570
MicroWorld-eScanGen:Heur.PonyStealer.hm0@nKazRfki
ALYacGen:Heur.PonyStealer.hm0@nKazRfki
CylanceUnsafe
ZillyaTrojan.Timer.Win32.1962
SangforHacktool.Win32.VBInject.gen
K7AntiVirusTrojan ( 002a00f51 )
AlibabaRansom:Win32/Timer.1f31a9e9
K7GWTrojan ( 002a00f51 )
BitDefenderThetaAI:Packer.9A69193320
CyrenW32/VBInject.1!Generic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.IBX
TrendMicro-HouseCallTROJ_RANSOM.AHY
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Timer.gxa
BitDefenderGen:Heur.PonyStealer.hm0@nKazRfki
NANO-AntivirusTrojan.Win32.Timer.cvnyj
SUPERAntiSpywareTrojan.Agent/Gen-VBKrypt
Ad-AwareGen:Heur.PonyStealer.hm0@nKazRfki
SophosML/PE-A + Mal/SpyEye-Q
ComodoMalware@#30ybujcnxm77m
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_RANSOM.AHY
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.00e515243f5aab04
EmsisoftGen:Heur.PonyStealer.hm0@nKazRfki (B)
IkarusTrojan.Win32.VBKrypt
GDataGen:Heur.PonyStealer.hm0@nKazRfki
JiangminTrojan.Timer.ca
WebrootW32.Ransom.Pornorolik
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.73D699
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/VBInject.gen!GQ
CynetMalicious (score: 100)
McAfeePWS-Zbot.gen.bbp
TACHYONTrojan/W32.VB-Agent.118784.DQ
VBA32Trojan.VB.WinLocker
PandaGeneric Malware
APEXMalicious
TencentWin32.Trojan.Timer.Fib
YandexTrojan.Timer!6kYmchyeyd0
MAXmalware (ai score=100)
eGambitGeneric.Malware
FortinetW32/Cycler.ALGQ!tr
AVGWin32:GenMalicious-KL [Trj]
Cybereasonmalicious.43f5aa
AvastWin32:GenMalicious-KL [Trj]
MaxSecureTrojan.Malware.2525020.susgen

How to remove Win32/Injector.IBX?

Win32/Injector.IBX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment