Trojan

Trojan.Win32.Injuke.hqzo removal guide

Malware Removal

The Trojan.Win32.Injuke.hqzo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Injuke.hqzo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Injuke.hqzo?


File Info:

name: 18EA82B906CBEA57081D.mlw
path: /opt/CAPEv2/storage/binaries/b7c8a90355b2bc0fb82adc3079d95f76428ef6098237deabd451e1a3103cd060
crc32: 2422AD4A
md5: 18ea82b906cbea57081d8c5d768e0f24
sha1: 295dc9c5a0914675620ab5005989b231a46f88e1
sha256: b7c8a90355b2bc0fb82adc3079d95f76428ef6098237deabd451e1a3103cd060
sha512: ccff1c5362906948328b9acab7931e6b2dcc8100663fe11c8f2f90bd90b07d8fdafcdc7ec5164485366f832ba0147a55a73987ca3d940878902bdcd62c8ed89e
ssdeep: 12288:EapniPD7biYzm2wqr52Wzbv2vK4pVYjuKoOcHReY09V3ddRJjqnRzsl5dnkTvspW:LpniXbjoAbv2vK4pVyoIBQIxnsvsduU+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130253382EF92CCB9EA628F743C58C2219223FC7A553C51BD3B9C4D0E9DB39C4845A756
sha3_384: 465fa1639af841f9fb72a5eccad2b6d6ee9759ce3e00416e5d15acf8c11186761fbc261ce14351845f986afe295c6fb0
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 2023-08-23 17:01:20

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: UX Previewer Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Win32.Injuke.hqzo also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injuke.16!c
Elasticmalicious (high confidence)
McAfeeArtemis!18EA82B906CB
Cylanceunsafe
SangforTrojan.Win32.Injuke.Vu80
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Injuke.hqzo
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Injuke.Fplw
F-SecureTrojan.TR/AD.Nekark.llpic
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
JiangminTrojan.Ekstak.chxb
WebrootW32.Trojan.Gen
AviraTR/AD.Nekark.llpic
ZoneAlarmTrojan.Win32.Injuke.hqzo
MicrosoftTrojan:Win32/Wacatac.B!ml
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0DHN23
MaxSecureTrojan.Malware.216144749.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Injuke.hqzo?

Trojan.Win32.Injuke.hqzo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment