Trojan

Trojan.Win32.Inject.amiml removal instruction

Malware Removal

The Trojan.Win32.Inject.amiml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Inject.amiml virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Inject.amiml?


File Info:

name: 79AA5878FF3111376D58.mlw
path: /opt/CAPEv2/storage/binaries/81954edbf4f98cf9254252462d35fbceb726fd9fac42b30414f531a4cd9842b5
crc32: 3C491CA6
md5: 79aa5878ff3111376d58a9173ecf9144
sha1: 6c402cf7c7884b77e1090e5ab99586371f764573
sha256: 81954edbf4f98cf9254252462d35fbceb726fd9fac42b30414f531a4cd9842b5
sha512: df0ad628339a3b2c7a2012963a59413dcd60e3f955a0bf98f6006f294f0a9d0463c6415c2a7d4de2c2181aaab269c9bdb719fb09be133f9c892019412909155d
ssdeep: 24576:OHCyeRyzkcRR0TZaqdiXSp0c02uFG6dAk3CMJ:OHCyezuCTZaqdwk0c05HGiJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14265F112B7F180F2C606253009BB2776AA748AD60B29EFC7E358DD6C5E732619D37139
sha3_384: f0f733e2f2bdad18540a2d05fc5052bcb49647936ed04cc162e00daade9e2fc7a0541a6d5f93d28f16ef1b8be98bd8ac
ep_bytes: 558bec6aff68d8ac5400688488450064
timestamp: 2013-02-07 04:57:22

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.Win32.Inject.amiml also known as:

LionicTrojan.Win32.Generic.lqzi
tehtrisGeneric.Malware
FireEyeGeneric.mg.79aa5878ff311137
MalwarebytesFlyStudio.Trojan.MalPack.DDS
K7AntiVirusTrojan ( 005246d51 )
K7GWAdware ( 004b87ea1 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.36196.Br0@aKmiUFgb
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
KasperskyTrojan.Win32.Inject.amiml
NANO-AntivirusTrojan.Win32.Inject.gfltwa
AvastWin32:Malware-gen
RisingTrojan.Inject!8.103 (CLOUD)
EmsisoftApplication.Generic (A)
F-SecureTrojan:W32/DelfInject.R
ZillyaTrojan.Inject.Win32.299619
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
JiangminTrojan.Inject.bats
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ZoneAlarmTrojan.Win32.Inject.amiml
GDataWin32.Trojan.PSE.1THOGOA
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!79AA5878FF31
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CEK23
YandexTrojan.GenAsa!JSEtYGta78o
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/MBRlock.AQ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.7c7884
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Inject.amiml?

Trojan.Win32.Inject.amiml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment