Malware

About “Win32/Injector.AALS” infection

Malware Removal

The Win32/Injector.AALS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AALS virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.AALS?


File Info:

crc32: 1027E38D
md5: 064ef0bf63029d099ed0ab83c32131f8
name: 064EF0BF63029D099ED0AB83C32131F8.mlw
sha1: 313bf1a7b754c56a5c3081c8759e3ca76628c2f8
sha256: e73b12bd51821036300d44b871b0ec1517649f3b5f7ad6ebfaf3015b81258893
sha512: d4077e8d8ecfa47ece3ed42dfb6d1c5b1e5588cacd32d8800c27f5029d3463ddea367e89e2dc0d9b31638a3b00c89caf567e4ae6b6ac41f79647261ec37adf74
ssdeep: 3072:bYWlCjnQllFKtQohSuGtsDeZU59oB0Q6FQUH3YMZrCbVNXkAnEDXfkzzaPB:bWQllF6QohSgq2Eu1HilBnoMzzKB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.AALS also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.655
CynetMalicious (score: 100)
CAT-QuickHealTrojanSpy.Zbot
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.42316
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Injector.2e695d28
Cybereasonmalicious.f63029
CyrenW32/VB.DT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AALS
APEXMalicious
AvastWin32:VB-TRP [Trj]
ClamAVWin.Trojan.Dusta-9833897-0
KasperskyTrojan-Spy.Win32.Zbot.brzx
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Zbot.fvkms
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan-spy.Zbot.Dva
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A
ComodoMalware@#2pqfp4x1vet0t
BitDefenderThetaAI:Packer.4C6DEA2D1F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DE521
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dc
FireEyeGeneric.mg.064ef0bf63029d09
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.froa
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MicrosoftPWS:Win32/Zbot
GDataTrojan.Ransom.Cerber.1
McAfeeArtemis!064EF0BF6302
MAXmalware (ai score=99)
VBA32Malware-Cryptor.VB.gen.1
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DE521
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!MVr4nqgOVwg
IkarusTrojan.Win32.Llac
FortinetW32/VBInjector.W!tr
AVGWin32:VB-TRP [Trj]

How to remove Win32/Injector.AALS?

Win32/Injector.AALS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment