Trojan

Trojan:Win32/Injector.CA information

Malware Removal

The Trojan:Win32/Injector.CA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Injector.CA virus can do?

  • Executable code extraction
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Injector.CA?


File Info:

crc32: F1DB3A78
md5: a58ad2806527c2ebc167d8a16d58e7ef
name: A58AD2806527C2EBC167D8A16D58E7EF.mlw
sha1: 1f915de7d97d5a9502e1b65b94457b2e669cbe18
sha256: dcc0e290653c0b28119f81bc77303ce45bf3542c707f89a5793a6d72c1f6449b
sha512: f58472482b6d07d2da1fb19016e0241411d6b7388f020e6b3d91b6112893e51e0746b5d2a732f904c2a715022796987ea6dbb3140f87e42c63da4239525f1028
ssdeep: 3072:FS722MyCgSvccUNVN3i8t3aicGK/shFVEDJ33/qW:FS63yChvccUNVN3i8tCd/scJ3yW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: Drammatico
FileVersion: 5.07.0008
CompanyName: Huawei
ProductName: BairSofts
ProductVersion: 5.07.0008
OriginalFilename: Drammatico.exe

Trojan:Win32/Injector.CA also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.lm0@dyfTV!nb
FireEyeGeneric.mg.a58ad2806527c2eb
Qihoo-360Win32/Trojan.PSW.bfb
McAfeeVBInject-FUC!A58AD2806527
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0050432f1 )
BitDefenderGen:Heur.PonyStealer.lm0@dyfTV!nb
K7GWTrojan ( 0050432f1 )
Cybereasonmalicious.06527c
CyrenW32/VBInject.ID.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
ClamAVWin.Trojan.VBPacked6-6043264-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Tepfer.elrfyd
AegisLabTrojan.Win32.Tepfer.i!c
Ad-AwareGen:Heur.PonyStealer.lm0@dyfTV!nb
SophosML/PE-A + Mal/FareitVB-I
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Heur.PonyStealer.lm0@dyfTV!nb (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112817
MAXmalware (ai score=82)
Antiy-AVLTrojan[PSW]/Win32.Tepfer
MicrosoftTrojan:Win32/Injector.CA
ArcabitTrojan.PonyStealer.EBD243F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.Kryptik.FY
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
VBA32BScope.Trojan.Dynamer
ALYacGen:Heur.PonyStealer.lm0@dyfTV!nb
MalwarebytesSpyware.Pony
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DKZL
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
TencentWin32.Trojan.Generic.Lmko
YandexTrojan.Injector!IM6Dn1Mk9c4
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.DKYM!tr
BitDefenderThetaGen:NN.ZevbaF.34804.lm0@ayfTV!nb
AVGWin32:InjectorX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Trojan:Win32/Injector.CA?

Trojan:Win32/Injector.CA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment