Malware

Should I remove “Troj/Inject-GNP”?

Malware Removal

The Troj/Inject-GNP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Inject-GNP virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Exhibits behavior characteristic of iSpy Keylogger
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file
  • Anomalous binary characteristics

How to determine Troj/Inject-GNP?


File Info:

crc32: 945F4B1B
md5: 491b5032691babc841e83246767aa5be
name: RFQ (2).exe
sha1: 42558032f6a165980742ad5278ca0f2db0d5c4c2
sha256: c2689bc7e035365f3aad0880c3f2526da7e6934882be23bef2b7fa20f4b04513
sha512: e10d97c476e9f3fc480dc992c43dfbd617ec0076e21b93ffbda1d40ff319bf3be87222bb7b6197654847ecb8d95027750984d7def4e861aa144a09b0f65c6f6f
ssdeep: 12288:o0vjWj3aKV1KBGJ7AEQi+95fd32koDTmWOuW3vvJAZ+u71o1HvSkf8R/LVWp7pAT:PqjKIUe7QLkbDTMrvSo2keVaBTxHDo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copkk d Softare Corp.
InternalName:
FileVersion: 6.0
CompanyName: BrlanSre Co.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 6.0
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Troj/Inject-GNP also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.25
MicroWorld-eScanTrojan.GenericKD.34723623
FireEyeGeneric.mg.491b5032691babc8
ALYacTrojan.Agent.HawkEye
MalwarebytesTrojan.MalPack
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34723623
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2f6a16
TrendMicroTrojan.Win32.WACATAC.THJAOBO
BitDefenderThetaGen:NN.ZelphiF.34566.dH0@aGqduKci
CyrenW32/Trojan.SKYF-1315
SymantecInfostealer.Lokibot!43
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Keylogger.Lokibot-9775682-0
AlibabaTrojanDropper:Win32/Lokibot.41fe717e
NANO-AntivirusTrojan.Win32.Kryptik.hzgvfy
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.34723623
SophosTroj/Inject-GNP
ComodoMalware@#1kvpeete53zdn
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Inject-GNP
McAfee-GW-EditionFareit-FZN!491B5032691B
EmsisoftTrojan.GenericKD.34723623 (B)
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Generic.D211D727
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataTrojan.GenericKD.34723623
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.C4205041
VBA32TScope.Trojan.Delf
MAXmalware (ai score=88)
ZonerTrojan.Win32.95727
ESET-NOD32Win32/TrojanDropper.Agent.RBR
TrendMicro-HouseCallTrojan.Win32.WACATAC.THJAOBO
RisingTrojan.Injector!1.CD4A (CLASSIC)
MaxSecureTrojan.Malware.73736783.susgen
FortinetW32/Injector.ENOR!tr
WebrootW32.Trojan.Gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.469

How to remove Troj/Inject-GNP?

Troj/Inject-GNP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment