Trojan

Trojan:Win32/Injuke.GMD!MTB removal tips

Malware Removal

The Trojan:Win32/Injuke.GMD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Injuke.GMD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Injuke.GMD!MTB?


File Info:

name: F6365429C448169F7016.mlw
path: /opt/CAPEv2/storage/binaries/99922ea5ea8a1c638e486189b515c9b2cea45df611d23fee11a3a33aa19a4479
crc32: 102DA8E4
md5: f6365429c448169f7016c1a438d6c4f8
sha1: 9ab6d1ddfc8e3e180c8841fdc8c183c6f1566f43
sha256: 99922ea5ea8a1c638e486189b515c9b2cea45df611d23fee11a3a33aa19a4479
sha512: 3ce9314c491ae376dfbfd8c519364ebe1e7171da3fc498ad47fcd8b6670a502bf553700b45b11c92ae5e407279e036eff5a3880d7f0761e9d27a346ebfb22a8e
ssdeep: 196608:t3EFUQz/scWsvkBol4yVGMpWRia0vlM2mxz9W8kLuiVaKcIAe91znD:t0FUQjsZukI4SG6W30vlM2oz9dkXAslT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164A6338166EF255CF424F1BA8BCBD33EF756B8E9694B0D3F1580128B47A86402F56873
sha3_384: 97c70c8bbcb6d3ee445117e488e6d0cdd0cfd71a51c7eb4ff1143cc18f933c5fe0af7a7bbe3a145f05a01f53116e93af
ep_bytes: b8e03229015064ff3500000000648925
timestamp: 2023-11-22 07:47:22

Version Info:

CompanyName: TODO:
FileDescription: PeMemoryRun20
FileVersion: 1.0.0.1
InternalName: PeMemoryRun20.exe
LegalCopyright: TODO: (C) 。 保留所有权利。
OriginalFilename: PeMemoryRun20.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Trojan:Win32/Injuke.GMD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Midie.139923
FireEyeGen:Variant.Midie.139923
SkyhighBehavesLike.Win32.Dropper.tc
McAfeeArtemis!F6365429C448
MalwarebytesTrojan.Crypt.Generic
SangforTrojan.Win32.Agent.V7o6
AlibabaTrojan:Win32/Injuke.6207bde1
ArcabitTrojan.Midie.D22293
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Midie.139923
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Midie.139923
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.wdyph
VIPREGen:Variant.Midie.139923
TrendMicroTROJ_GEN.R002C0DL423
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Midie.139923 (B)
AviraTR/Redcap.wdyph
Antiy-AVLTrojan[Dropper]/Win32.Convagent
MicrosoftTrojan:Win32/Injuke.GMD!MTB
GDataGen:Variant.Midie.139923
GoogleDetected
AhnLab-V3Dropper/Win.Generic.C5557282
ALYacGen:Variant.Midie.139923
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DL423
RisingTrojan.Znyonm!8.18A3A (CLOUD)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.220836648.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.36608.@p0aaqAQX0h
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Injuke.GMD!MTB?

Trojan:Win32/Injuke.GMD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment