Trojan

Trojan.Win32.DllHijack removal instruction

Malware Removal

The Trojan.Win32.DllHijack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.DllHijack virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.DllHijack?


File Info:

name: F8E2FE1F8D2A8E8D7F52.mlw
path: /opt/CAPEv2/storage/binaries/0dd891c37c73e25712ecb79aaec18e114e46973a10d8d3b2f74fe6c7a49998a9
crc32: F16AA5B8
md5: f8e2fe1f8d2a8e8d7f5288094ecff8b8
sha1: 81016af85f553ed84a789f6fe21b44484d3e888e
sha256: 0dd891c37c73e25712ecb79aaec18e114e46973a10d8d3b2f74fe6c7a49998a9
sha512: ad1bc51955a1642ad08ccba1e505dbfa9b347ffd317dd96419ea3d58bdc4f64f1a77281f93b786a3b6a68a97eb57ceb17e0353fd113e63c34ef693c963d3f7a9
ssdeep: 98304:OHCHqMh1yz8QGFI+5s/XdrqgHCHqMh1yz8QGFI+5s/V0rqCo2p6hwJJYBkFELWnD:CCHqZl3CHqZm7nsBelSe/T5toog7IGi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5D69D317286C43EC56615B2192C9EAF6128BE330BB159DB73DC3E6E4AB54C20736E17
sha3_384: 010b6a6f676ea0151227f65a35cb180ea2e61ce232327e907ae5b67434220ee8cac65bbd43345c3532ae036225ebb179
ep_bytes: e846060000e97afeffff8b4df464890d
timestamp: 2023-01-30 13:56:56

Version Info:

CompanyName: Electro Team
FileDescription: Electro Installer
FileVersion: 1.0.1.4
InternalName: Installer
LegalCopyright: Copyright (C) 2023 Electro Team
OriginalFileName: Installer.exe
ProductName: Electro
ProductVersion: 1.0.1.4
Translation: 0x0409 0x04b0

Trojan.Win32.DllHijack also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.DllHijack.4!c
CAT-QuickHealTrojan.DLLhijack
McAfeeArtemis!F8E2FE1F8D2A
SangforTrojan.Win32.Dllhijack.V6t3
AlibabaTrojan:Win32/DllHijack.0740e3f4
CyrenW32/ABRisk.QSXE-4187
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Trojan.Win32.DllHijack.gen
AvastFileRepMalware [Misc]
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
SophosGeneric Reputation PUA (PUA)
ZoneAlarmHEUR:Trojan.Win32.DllHijack.gen
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H07EQ23
RisingTrojan.Generic@AI.100 (RDML:25kBqahgQsAjC+Jj0S8jrw)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.74225798.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.DllHijack?

Trojan.Win32.DllHijack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment