Trojan

Should I remove “Trojan.Win32.Inject.aleec”?

Malware Removal

The Trojan.Win32.Inject.aleec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Inject.aleec virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Attempts to bypass application whitelisting by executing .NET utility in a suspended state, potentially for injection
  • CAPE detected the HawkEyev9 malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Trojan.Win32.Inject.aleec?


File Info:

name: 52D4245D65D5CC2DA052.mlw
path: /opt/CAPEv2/storage/binaries/70ef3c88a90dd590de9a0ac4634b5017f35ea6dedec14f3cc3b5d9eeb3ca84a2
crc32: 48FFAD0C
md5: 52d4245d65d5cc2da05298c480ffcc5f
sha1: b2ecf335eb93feba2cf923419e70d7b6cff79061
sha256: 70ef3c88a90dd590de9a0ac4634b5017f35ea6dedec14f3cc3b5d9eeb3ca84a2
sha512: ab847b2e12b9ef8e494688094260967f42f8c0dc6797d635162b64fb32ac8720a2051441128b5a0528eeabe0fc8f5b8dafda15d688721037a2734e5e0629b02f
ssdeep: 24576:8AHnh+eWsN3skA4RV1Hom2KXMmHaurntQLuyoI4f+O2fRHonhhlvXGE3nR5:bh+ZkldoPK8Yaux3b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186A5C0C6E39580E2FD0667F79E24F6834B395E354532401D27AE3D6A6E730F2412DAA3
sha3_384: f9d6f014f7a359d4153cd7b51db621e504dd99a9fee41964ee5d308dd3438eab952e1d90cff4ff300e21ba44cb53e8ae
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-01-29 11:36:35

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Inject.aleec also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AutoIt.Wacatac.E
ALYacTrojan.GenericKD.41003103
CylanceUnsafe
K7AntiVirusTrojan ( 005469331 )
AlibabaVirTool:Win32/AutInject.6fd60c5d
K7GWTrojan ( 005469331 )
Cybereasonmalicious.d65d5c
CyrenW32/FakeDoc.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.aleec
BitDefenderTrojan.GenericKD.41003103
NANO-AntivirusTrojan.Win32.AutoIt.fmmxpj
MicroWorld-eScanTrojan.GenericKD.41003103
AvastAutoIt:Injector-JF [Trj]
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.41003103
SophosMal/Generic-S + Mal/AuItInj-A
ComodoMalware@#wpgjjg85s07d
F-SecureHeuristic.HEUR/AGEN.1207788
DrWebTrojan.AutoIt.316
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.52d4245d65d5cc2d
EmsisoftTrojan.GenericKD.41003103 (B)
IkarusTrojan.Autoit
GDataTrojan.GenericKD.41003103
AviraHEUR/AGEN.1207788
Antiy-AVLTrojan/Generic.ASCommon.151
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D271A85F
ViRobotTrojan.Win32.Z.Autoit.2135040
MicrosoftTrojan:AutoIt/CryptInject.J
AhnLab-V3Trojan/Win32.AutoIT.R257197
McAfeeArtemis!52D4245D65D5
MAXmalware (ai score=82)
VBA32Trojan.Inject
MalwarebytesTrojan.Injector.AutoIt.Generic
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
eGambitUnsafe.AI_Score_100%
FortinetAutoIt/Packed.OV!tr
BitDefenderThetaAI:Packer.1CBAB21B17
AVGAutoIt:Injector-JF [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.3157.susgen

How to remove Trojan.Win32.Inject.aleec?

Trojan.Win32.Inject.aleec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment