Trojan

UDS:Trojan.Win32.Inject.sb removal tips

Malware Removal

The UDS:Trojan.Win32.Inject.sb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Inject.sb virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates known XtremeRAT mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine UDS:Trojan.Win32.Inject.sb?


File Info:

crc32: 5EAA6792
md5: 2356c9b50cd3a0b78a3d69ae2295a9ef
name: 2356C9B50CD3A0B78A3D69AE2295A9EF.mlw
sha1: 5082c93ef4d3b67af5b3f23866cbc0ce4b9ca8bd
sha256: 2ec1c2129af1276ae8fdcbf619afcba434ae8923a3b29422d1c34a12ce4809f8
sha512: 15449912212368103781cdf98ec8b5fc1edb916049f50fac969c09e538ca3117e9454bce2b2f102b0f37dcd63eb3efa28ad58c7b2fa7625f010f8d60e03399cc
ssdeep: 24576:BAHnh+eWsN3skA4RV1Hom2KXMmHadznBOY9f0TUpYjpgeeK4hNOaX5Wds5:Yh+ZkldoPK8YahpcveK4hNOaY4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

UDS:Trojan.Win32.Inject.sb also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.40399337
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Script/Injector.1ad4360c
Cybereasonmalicious.50cd3a
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Injector-W [Trj]
KasperskyUDS:Trojan.Win32.Inject.sb
BitDefenderTrojan.GenericKD.40399337
NANO-AntivirusTrojan.Win32.CoinMiner.fgtdvt
MicroWorld-eScanTrojan.GenericKD.40399337
Ad-AwareTrojan.GenericKD.40399337
SophosMal/Generic-S
ComodoMalware@#ortqpl8k5o5y
BitDefenderThetaAI:Packer.E29A7AB517
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
FireEyeGeneric.mg.2356c9b50cd3a0b7
EmsisoftTrojan.GenericKD.40399337 (B)
AviraHEUR/AGEN.1100130
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Xtrat.A
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.40399337
McAfeeArtemis!2356C9B50CD3
MAXmalware (ai score=100)
VBA32Trojan.Inject
MalwarebytesTrojan.BitCoinMiner
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CIP21
IkarusTrojan.Win32.CoinMiner
FortinetAutoIt/Injector.ANX!tr
AVGAutoIt:Injector-W [Trj]
Paloaltogeneric.ml

How to remove UDS:Trojan.Win32.Inject.sb?

UDS:Trojan.Win32.Inject.sb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment