Malware

Win32/Injector.IRE removal guide

Malware Removal

The Win32/Injector.IRE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.IRE virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Win32/Injector.IRE?


File Info:

crc32: 4D84DEE6
md5: feb5bf5f8a19b05654ceaa85f87243c7
name: FEB5BF5F8A19B05654CEAA85F87243C7.mlw
sha1: 6c31278bba226f1dadda958def26fc74996da3b3
sha256: 34601886faa2efbc8f5a8208c834a2ae0fdef15909518f69e2f5a8b75f616841
sha512: cf6891221de0390e7e74205c46fb7e60b5bd2f49d9d272f0662627063a87695fedff33ee01dfbec81f75f69d369d1767ac2837e70ea84b40b83b21854985f8cd
ssdeep: 49152:nHi2DcM5byZ97edaq92PTNlO/yzETw3FQeBjUIdLhK9E22z:nCw5byZ9GoGgFQe+IdLc9E20
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: YhF
InternalName: Project1
FileVersion: 2.00.0001
CompanyName: DVEb
LegalTrademarks: PKKJ
Comments: vLjkLUg
ProductName: mDHJBaph
ProductVersion: 2.00.0001
FileDescription: File Description
OriginalFilename: Project1.exe

Win32/Injector.IRE also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.61630
ClamAVWin.Trojan.Injector-179
ALYacGen:Variant.Barys.1409
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Barys.1409
Cybereasonmalicious.f8a19b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.IRE
ZonerProbably Heur.ExeHeaderP
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Injector.bxo
MicroWorld-eScanGen:Variant.Barys.1409
Ad-AwareGen:Variant.Barys.1409
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34266.ewKfaymvSHdi
FireEyeGeneric.mg.feb5bf5f8a19b056
EmsisoftGen:Variant.Barys.1409 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Injector.ln
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.B0F94
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Barys.1409
VBA32TScope.Trojan.VB
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_PAM_0000010066.T3
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazp/VgKeyr2iMTJIdnayXvRV)
YandexTrojan.GenAsa!PSWoo4EBJnc
IkarusGen.Trojan.Heur
FortinetW32/Refroso.DZP!tr

How to remove Win32/Injector.IRE?

Win32/Injector.IRE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment