Trojan

Trojan.Win32.Inject.anyqe removal guide

Malware Removal

The Trojan.Win32.Inject.anyqe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Inject.anyqe virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Trojan.Win32.Inject.anyqe?


File Info:

name: 39D6F2D22D826DDD3B0A.mlw
path: /opt/CAPEv2/storage/binaries/53b7625e48edc0e7ee464b1168c4ed3101bdab155b338dee80c58baa7442363c
crc32: 88CF2110
md5: 39d6f2d22d826ddd3b0aa768067ff2a5
sha1: 4fde6d6eb8d83dc480f9fc6f43271d19214ee8e3
sha256: 53b7625e48edc0e7ee464b1168c4ed3101bdab155b338dee80c58baa7442363c
sha512: 05aac20fd11c4cb61b20d94dd749e74362b79e720c97663ae9751fcfbdfcf667f0da7b2fff8cdc499cedab3a4bb9fcd056328af3a3ffe58cb6b047c9ab5fa74b
ssdeep: 6144:rGi4FzFQatbrf/nLzlJnL9CMzYnIOYtFgPS6aeBZ:UxFQatbrXnLzlJn4MT7tFga6aAZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA64231273C0EBA7DA51D2300E33916FE7BF436032DB29179B497F2B6C625D2960A497
sha3_384: 8a3bb13611e901ebccc553182cfb751f90cbceeddc0ce7092a4ac6ad1d2d3b59f57e90014a7c18ca7d9034e9efc0c113
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan.Win32.Inject.anyqe also known as:

LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47616472
FireEyeTrojan.GenericKD.47616472
CAT-QuickHealTrojan.Inject
McAfeeArtemis!39D6F2D22D82
CylanceUnsafe
SangforTrojan.Win32.Inject.ky
K7AntiVirusTrojan ( 0058b9d81 )
AlibabaTrojanSpy:Win32/Lokibot.3571139b
K7GWTrojan ( 0058b9d81 )
Cybereasonmalicious.22d826
ArcabitTrojan.Generic.D2D691D8
CyrenW32/Injector.ARQ.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EQSP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.anyqe
BitDefenderTrojan.GenericKD.47616472
NANO-AntivirusTrojan.Win32.Inject.jjcicx
AvastWin32:PWSX-gen [Trj]
TencentNsis.Trojan.Nsisx.Lnes
Ad-AwareTrojan.GenericKD.47616472
SophosGeneric ML PUA (PUA)
DrWebTrojan.Siggen16.3134
ZillyaTrojan.Inject.Win32.317006
TrendMicroTROJ_GEN.R03FC0WLD21
McAfee-GW-EditionGenericRXRB-OZ!53F7B0E9A3E8
EmsisoftTrojan.GenericKD.47616472 (B)
IkarusTrojan.NSIS.Agent
JiangminTrojan.Inject.cbwh
AviraTR/Injector.xqhxc
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Lokibot.VALC!MTB
ViRobotTrojan.Win32.Z.Undef.310919
GDataWin32.Trojan-Stealer.FormBook.HHB7PO
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47616472
MAXmalware (ai score=81)
FortinetW32/Kryptik.EQRK!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Inject.anyqe?

Trojan.Win32.Inject.anyqe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment