Trojan

How to remove “Trojan.Inject.AXX”?

Malware Removal

The Trojan.Inject.AXX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Inject.AXX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Inject.AXX?


File Info:

name: 353EFD97AD000F26A44E.mlw
path: /opt/CAPEv2/storage/binaries/c8794f1ae49442e7eef1e6ab532bf9fa43088b157eacc8fb67a1380582991ff7
crc32: 777CFCC7
md5: 353efd97ad000f26a44e4f3614729bfd
sha1: 4bbaef8e711b22f6d1a82de2296481b30f23f635
sha256: c8794f1ae49442e7eef1e6ab532bf9fa43088b157eacc8fb67a1380582991ff7
sha512: 6d2487c9496e29d700f41101f5d210857187863bc0cff8254104ad1f4f6c9cf90a837416009092d32fe2e4ada482d83df7f54615431eda4457baffa78ef5ea65
ssdeep: 768:NOPZMJU8aPvQ8HxcE4e3lkB0qdTQ6ZL6iKfz3ZS23KiRjG6BvfO56zwnpoiwIF:NUGJU82lHG2CB0M7crfBvfOHNbF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D83D05FD2B0B727D4BEF8B019BE071B6392AA264E75D6237E441F4D1C311166E1224F
sha3_384: 53caf9124841f6f6c003ff6dd9181c9c1b16d270172f360bc00a36390190a8f7abdc8e754efb1b0dec70a314ce6796ca
ep_bytes: 558bec6a0068503a400068e222400064
timestamp: 2015-06-28 07:28:10

Version Info:

0: [No Data]

Trojan.Inject.AXX also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Hlux.tnFY
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Inject.AXX
FireEyeGeneric.mg.353efd97ad000f26
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-EZ!353EFD97AD00
CylanceUnsafe
SangforBackdoor.Win32.Hlux.8
K7AntiVirusTrojan ( 004c7e1e1 )
AlibabaBackdoor:Win32/DllCheck.bb19e93a
K7GWTrojan ( 004c7e1e1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Inject.AXX
BitDefenderThetaGen:NN.ZexaF.34638.fqZ@a4gIYnFH
VirITTrojan.Win32.Inject2.CLYH
CyrenW32/Kelihos.E.gen!Eldorado
SymantecTrojan.Fareit!gen1
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.CDUI
BaiduWin32.Trojan.Injector.j
TrendMicro-HouseCallTROJ_CRYPWALL.SMF
Paloaltogeneric.ml
ClamAVWin.Malware.Bldx-6933282-0
KasperskyBackdoor.Win32.Hlux.dca
BitDefenderTrojan.Inject.AXX
NANO-AntivirusTrojan.Win32.Hlux.dtqfpd
AvastWin32:Injector-CSV [Trj]
TencentMalware.Win32.Gencirc.10b0ee83
Ad-AwareTrojan.Inject.AXX
EmsisoftTrojan.Inject.AXX (B)
ComodoBackdoor.Win32.Hlux.AMG@5sucfd
DrWebTrojan.DownLoader14.49148
TrendMicroTROJ_CRYPWALL.SMF
McAfee-GW-EditionPacked-EZ!353EFD97AD00
SophosML/PE-A + Mal/Zbot-UE
APEXMalicious
JiangminBackdoor/Hlux.glq
AviraTR/Inject.sbbeina
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Hack.Hlux.d.(kcloud)
MicrosoftTrojan:Win32/DllCheck.A!MSR
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmBackdoor.Win32.Hlux.dca
GDataTrojan.Inject.AXX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R156859
ALYacTrojan.Inject.AXX
TACHYONBackdoor/W32.Hlux.82634
VBA32OScope.Malware-Cryptor.Hlux
IkarusTrojan.Win32.Injector
RisingBackdoor.Hlux!8.159 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.1F2DDD!tr
AVGWin32:Injector-CSV [Trj]
Cybereasonmalicious.7ad000
PandaTrj/Agent.CKO

How to remove Trojan.Inject.AXX?

Trojan.Inject.AXX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment