Trojan

Trojan.Win32.Inject.jzai removal

Malware Removal

The Trojan.Win32.Inject.jzai is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Inject.jzai virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Accessed credential storage registry keys
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine Trojan.Win32.Inject.jzai?


File Info:

name: 042320D4127A678F7BDE.mlw
path: /opt/CAPEv2/storage/binaries/6fbdcb19b7fcd27659c96bcd06455bb4ff8456b5698ec63c4bff304a4315f864
crc32: D83DFCD4
md5: 042320d4127a678f7bde03f331134a1d
sha1: 54b44d57b58caa12c4f4c2eeecda3b05cce89b37
sha256: 6fbdcb19b7fcd27659c96bcd06455bb4ff8456b5698ec63c4bff304a4315f864
sha512: 20e69647e144b13307e154d63aaec5f0ea241c9f1975201f6df5e221b4a54bbb48cbb43ae2fc8bfcf674af1fa20166fe223f9a1b99c9e1358c826570772949dc
ssdeep: 3072:DQIURTXJ+Mdk9SoJBt6p6QMPdfc5r56bM2WCa5/4UkvWJVxh6vps:Ds9dr6t6Ad0N1FCO4UpJcvps
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FE3025A31C0D0BBD5930B711A7ADBABE7F997001653038BAB104E7F76240D7EA6A2D1
sha3_384: d5f4a8918792525eb0c1cc08af3559f6ad6f847501cb4d12aa27a683ef103edec58a01543cffaf9d6ce1e16de297e56e
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Trojan.Win32.Inject.jzai also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Inject.lN4U
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.jm0@nuA!z9ob
FireEyeGeneric.mg.042320d4127a678f
CAT-QuickHealVirTool.VBInject.LE3
McAfeeArtemis!042320D4127A
CylanceUnsafe
ZillyaTrojan.Inject.Win32.74663
SangforTrojan.Win32.Boaxxe.BL
K7AntiVirusTrojan ( 0055e3f51 )
BitDefenderGen:Heur.PonyStealer.jm0@nuA!z9ob
K7GWTrojan ( 0055e3f51 )
Cybereasonmalicious.4127a6
ArcabitTrojan.PonyStealer.E3A267
BitDefenderThetaGen:NN.ZevbaF.34582.jm0@auA!z9ob
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Boaxxe.BL
TrendMicro-HouseCallTROJ_INJECT.YPME
KasperskyTrojan.Win32.Inject.jzai
AlibabaVirTool:Win32/VBInject.1ca527bf
NANO-AntivirusTrojan.Win32.Inject.czxcpw
RisingDropper.Miuref!8.2CCB (CLOUD)
SophosMal/Generic-S
ComodoMalware@#g8u2dxi40t41
F-SecureHeuristic.HEUR/AGEN.1225523
DrWebTrojan.Boaxxe.2
VIPREGen:Heur.PonyStealer.jm0@nuA!z9ob
TrendMicroTROJ_INJECT.YPME
McAfee-GW-EditionTrojan-FDSP!AE5966670BE8
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.PonyStealer.jm0@nuA!z9ob (B)
APEXMalicious
AviraHEUR/AGEN.1233707
Antiy-AVLTrojan/Win32.Inject
KingsoftWin32.Troj.Inject.jz.(kcloud)
MicrosoftVirTool:Win32/VBInject.gen!LN
SUPERAntiSpywareTrojan.Agent/Gen-Tracur
ZoneAlarmTrojan.Win32.Inject.jzai
GDataGen:Heur.PonyStealer.jm0@nuA!z9ob
CynetMalicious (score: 100)
VBA32Trojan.Wacatac
ALYacGen:Heur.PonyStealer.jm0@nuA!z9ob
MAXmalware (ai score=100)
MalwarebytesTrojan.Happili
PandaTrj/CI.A
YandexTrojan.Inject!ExRu2u5aDVI
SentinelOneStatic AI – Suspicious PE
FortinetW32/Zbot.RZIM!tr
AVGNSIS:Dropper-IT [Drp]
AvastNSIS:Dropper-IT [Drp]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Inject.jzai?

Trojan.Win32.Inject.jzai removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment