Trojan

How to remove “Trojan.Win32.Inject.anyjb”?

Malware Removal

The Trojan.Win32.Inject.anyjb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Inject.anyjb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Inject.anyjb?


File Info:

name: 5D10C77689E0C3BEA850.mlw
path: /opt/CAPEv2/storage/binaries/8a0fb297baf6f3affb73e0c20116dec0bbbae0292fcbffc3948051555df5099d
crc32: 438958D5
md5: 5d10c77689e0c3bea850fa3c9ef40e8c
sha1: 35dca95d10a31fe0b1832f43005c0a79a6854604
sha256: 8a0fb297baf6f3affb73e0c20116dec0bbbae0292fcbffc3948051555df5099d
sha512: 920b5f4c55db41e225bb760a2d26b4aec8fed0d3d66392bbe8acf91cec35097e0934a2559661dd45eaa5b2303c102eedb4c88aef91e024c05b78d6cf289f795a
ssdeep: 6144:wGiztEIOcZis3bJTEppPWz1xJ1AuSwDZOQIPYnXq8gYg+xhWXvgB1Zd4PU2u:ybsmFTsU1xJztZ3m6gmL441ZdoPu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DDB4018A6068542ACAD4713EAFB0DEF953B09DCD180556771FF47E9B3AFD09712023A2
sha3_384: 5bb80d7b582b22cf7b5608d4e9824d069545c07c299f5cf543905eae2ad35e0ad9ce5d0c4d4355e93a904b0d3315359e
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan.Win32.Inject.anyjb also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38202588
CAT-QuickHealTrojan.Lokibot
McAfeeRDN/Generic.cf
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.689e0c
CyrenW32/Injector.ARK.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQRW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.anyjb
BitDefenderTrojan.GenericKD.38202588
AvastWin32:InjectorX-gen [Trj]
Ad-AwareTrojan.GenericKD.38202588
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.oerzz@0
DrWebTrojan.Siggen16.42
TrendMicroTROJ_FRS.0NA103L721
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
EmsisoftTrojan.GenericKD.38202588 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Stealer.FormBook.KV7TL0
AviraTR/Injector.zlxmg
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Lokibot.SIS!MTB
AhnLab-V3Trojan/Win.Lokibot.C4818113
MAXmalware (ai score=100)
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.2834833801
TrendMicro-HouseCallTROJ_FRS.0NA103L721
FortinetW32/Injector.EQRT!tr
WebrootW32.Trojan.GenKD
AVGWin32:InjectorX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Inject.anyjb?

Trojan.Win32.Inject.anyjb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment