Trojan

How to remove “Trojan.Win32.Inject.anypt”?

Malware Removal

The Trojan.Win32.Inject.anypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Inject.anypt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Inject.anypt?


File Info:

name: 62533E696B6D0B88ADC8.mlw
path: /opt/CAPEv2/storage/binaries/c07d31aae9f9676664b312e521c8bf0e22e08262d5b531b7010069f844100d3d
crc32: ABF7CD4A
md5: 62533e696b6d0b88adc8f975630079c9
sha1: d750759e8d4de9e52a9c1de95565308b2e0e5426
sha256: c07d31aae9f9676664b312e521c8bf0e22e08262d5b531b7010069f844100d3d
sha512: 08abb4da39057728fa48636ab98153121cd48dffe04339f37bba063d942aaff8d151f1a240757f987efee7812d5fb0ec758f5410644a6f7a233b811fc7a9482e
ssdeep: 6144:rGiqQGrlDdWo1pso15zFgN5vWdGnB/fjhC436xxzl5mnXw2V:fG9dT7so1Y3Wd6CI6xTkV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15264234AAAC25AF7DB644E711572B6B8F3BC43D022930663CB3C1C66D9F6B17D520682
sha3_384: 628d50ae4749b164029694de8eb3f9118655fc01c74c45471a756fb9d97d02ea90c44a2d38dcfc0200b31b9c61ffc17f
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan.Win32.Inject.anypt also known as:

LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38235484
FireEyeTrojan.GenericKD.38235484
ALYacTrojan.GenericKD.38235484
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058b9d81 )
AlibabaTrojanSpy:Win32/Tnega.8424c203
K7GWTrojan ( 0058b9d81 )
CyrenW32/Injector.ARQ.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EQSP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.anypt
BitDefenderTrojan.GenericKD.38235484
NANO-AntivirusTrojan.Win32.Inject.jixiak
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan.Inject.Wmit
Ad-AwareTrojan.GenericKD.38235484
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.vcuqg@0
DrWebTrojan.Siggen16.2998
TrendMicroTROJ_FRS.VSNTLA21
McAfee-GW-EditionRDN/Formbook
EmsisoftTrojan.GenericKD.38235484 (B)
GDataWin32.Trojan-Stealer.FormBook.J2YWZG
JiangminTrojan.Inject.cbpl
WebrootW32.Trojan.Gen
AviraTR/Injector.zeujx
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2476D5C
ViRobotTrojan.Win32.Z.Sabsik.313941
MicrosoftTrojan:Win32/Tnega.PAL!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4830475
McAfeeRDN/Formbook
MAXmalware (ai score=86)
VBA32TrojanSpy.Noon
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_FRS.VSNTLA21
YandexTrojan.Igent.bW5y0i.9
IkarusTrojan.NSIS.Agent
FortinetW32/Kryptik.EQRK!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Inject.anypt?

Trojan.Win32.Inject.anypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment