Trojan

Trojan.Win32.Injuke.kcc removal guide

Malware Removal

The Trojan.Win32.Injuke.kcc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Injuke.kcc virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
appealingedge.xyz

How to determine Trojan.Win32.Injuke.kcc?


File Info:

crc32: D6EE1918
md5: d559cbd94d9ff67eb13a09e9594237b1
name: upload_file
sha1: a6fa80a1ae038e71fa61487bb87fe767073b868f
sha256: 64ed137c6c4cc22533337a8acf615e2e95f6a7fc3e376dcfafcd5af6d5f05231
sha512: 7bd5d24c246541d3e44a958b6f8b0f3985d0d422c8821596a246bf34ee6639cf4cfa52b479ed10d09f452d4ec4b79d10054d9ff865e48ee808652841c8630a94
ssdeep: 3072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX: @x10x01FileVersion
edbit: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXX: |,x01LegalCopyright
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX: ?,x01FileDescription
CompanyName: speedbit
Translation: 0x0409 0x04e4

Trojan.Win32.Injuke.kcc also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Fugrafa.69861
FireEyeGeneric.mg.d559cbd94d9ff67e
Qihoo-360Win32/Trojan.500
McAfeePacked-GCB!D559CBD94D9F
CylanceUnsafe
ZillyaTrojan.Gozi.Win32.3046
SangforMalware
K7AntiVirusTrojan ( 0056b69c1 )
BitDefenderGen:Variant.Fugrafa.69861
K7GWTrojan ( 0056b69c1 )
Cybereasonmalicious.1ae038
Invinceaheuristic
F-ProtW32/Fugrafa.K.gen!Eldorado
SymantecInfostealer.Snifula
Paloaltogeneric.ml
GDataGen:Variant.Fugrafa.69861
KasperskyTrojan.Win32.Injuke.kcc
AlibabaTrojan:Win32/Injuke.b76cfb73
ViRobotTrojan.Win32.Z.Gozi.256364
AegisLabTrojan.Win32.Gozi.trsf
RisingTrojan.MalCert!1.C99C (CLASSIC)
Ad-AwareGen:Variant.Fugrafa.69861
EmsisoftGen:Variant.Fugrafa.69861 (B)
F-SecureTrojan.TR/Gozi.yvyxa
DrWebTrojan.Gozi.703
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DGV20
Trapminemalicious.high.ml.score
SophosMal/EncPk-APV
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.ODDW-0108
JiangminTrojan.Banker.Gozi.bah
AviraTR/Gozi.yvyxa
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
Endgamemalicious (high confidence)
ArcabitTrojan.Fugrafa.D110E5
ZoneAlarmTrojan.Win32.Injuke.kcc
MicrosoftTrojan:Win32/Qakbot.AR!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Kryptik.C4170640
Acronissuspicious
ALYacGen:Variant.Fugrafa.69861
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFGZ
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
SentinelOneDFI – Malicious PE
FortinetW32/Agent.900E!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan.Win32.Injuke.kcc?

Trojan.Win32.Injuke.kcc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment