Malware

Should I remove “Troj/Inject-GNQ”?

Malware Removal

The Troj/Inject-GNQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Inject-GNQ virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Troj/Inject-GNQ?


File Info:

crc32: EF322D79
md5: 3e2801a7dcb7011c03ba27f73b046ee8
name: upload_file
sha1: 1927ff0b8e28a29dd8d99f486d5cee943346571c
sha256: d3473a3e73cf0e6c3d25f6631d4b4929f25f14d3997ab4a64f51530314dfb4d3
sha512: ffdd92b8d77c3c3ff3ba4253fcd8773e181b0220b80c887def0d26789af27547edbdd69e29f14d8a5ea58d169b1ac8dfc32c562e58be9d6c11d73f4288914b59
ssdeep: 12288:gAindXhz+XwfE0CQPW7q0dzQNqJHRrUtq/9q+Pw5fQUMFi:Xi16wf9aNzQ4lFUtq0+PwIi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copk Softare Corp.
InternalName:
FileVersion: 6f0
CompanyName: BrlanlSre Co.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 6z5.0
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Troj/Inject-GNQ also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34749744
FireEyeGeneric.mg.3e2801a7dcb7011c
McAfeeRDN/SpamMlwr
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00570de21 )
BitDefenderTrojan.GenericKD.34749744
K7GWTrojan ( 00570de21 )
Cybereasonmalicious.b8e28a
InvinceaMal/Generic-S + Troj/Inject-GNQ
CyrenW32/Injector.IWML-6060
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9777076-0
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
ViRobotTrojan.Win32.Z.Kryptik.684032.AWV
RisingTrojan.Injector!1.CD4A (CLASSIC)
Ad-AwareTrojan.GenericKD.34749744
SophosTroj/Inject-GNQ
ComodoMalware@#4ce9bcjt4shn
DrWebBackDoor.SpyBotNET.17
TrendMicroTrojanSpy.Win32.INJECTOR.USMANJC20
McAfee-GW-EditionRDN/SpamMlwr
EmsisoftTrojan.GenericKD.34749744 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.Kryptik.cmk
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/LokibotCrypt.RK!MTB
ArcabitTrojan.Generic.D2123D30
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataWin32.Trojan.PSE.VH2U3I
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R353017
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34570.PG0@aSDoPrji
MAXmalware (ai score=83)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
ZonerTrojan.Win32.95824
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTrojanSpy.Win32.INJECTOR.USMANJC20
TencentWin32.Trojan.Kryptik.Lkxs
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.ETYV!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM05.1.D3A0.Malware.Gen

How to remove Troj/Inject-GNQ?

Troj/Inject-GNQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment