Malware

Win32/Injector.AEKN (file analysis)

Malware Removal

The Win32/Injector.AEKN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AEKN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Win32/Injector.AEKN?


File Info:

name: C68377A60A5068C6DCF0.mlw
path: /opt/CAPEv2/storage/binaries/a68017aea88ed090e5fcb6b2894252dc85dbb4b0725d961488a6cafa8e5e46c6
crc32: A7735377
md5: c68377a60a5068c6dcf0bc4f1d14f374
sha1: 47a77a1aa7a79646a7c19004451eb0cc483140c7
sha256: a68017aea88ed090e5fcb6b2894252dc85dbb4b0725d961488a6cafa8e5e46c6
sha512: f17c4dffa0e315938251a2d5e6c21ed1c14629e6f1b06113a16216f3de3444eaa2cc941691073e018f7e8dad323ca0e4ea7c5bef9a1c5a245ca7c6530013fc1e
ssdeep: 3072:hJ3Jet2WRPLvzFgYhhRvJ5OK+PjayXXd9EBG68ZMNUI875vytmOu:YLRvjOK++yXN9EBG68ZK81m/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B24A235A18B8C39FEAD87715BAC36A7B3DBA86C6C00C04510B5251CD97EE53E9A1D0B
sha3_384: b5e41c7bd130689e77591c66656619156980e560526b71d27e469039121360caae2c2e32b0330a3f53e343fcd149366a
ep_bytes: 688c174000e8eeffffff000000000000
timestamp: 2011-05-12 03:10:54

Version Info:

Translation: 0x0409 0x04b0
Comments: omsbfgea
CompanyName: kypnqcitiupibav
FileDescription: tluhekdnywzlfqec
LegalCopyright: lxkixu
LegalTrademarks: yhlm
ProductName: jdhcgzxkypnq
FileVersion: 29.17.0024
ProductVersion: 29.17.0024
InternalName: efffr
OriginalFilename: efffr.exe

Win32/Injector.AEKN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blocker.V!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.nm1@iunmvabi
FireEyeGeneric.mg.c68377a60a5068c6
SkyhighPWS-Zbot.gen.aye
McAfeePWS-Zbot.gen.aye
Cylanceunsafe
ZillyaTrojan.Blocker.Win32.27113
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.33ed5e6f
BitDefenderThetaAI:Packer.BA81650020
VirITWorm.Win32.X-Aurun.CVTY
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.AEKN
APEXMalicious
TrendMicro-HouseCallRansom_Blocker.R002C0DAO24
ClamAVWin.Trojan.Agent-515890
KasperskyTrojan-Ransom.Win32.Blocker.bpwg
BitDefenderGen:Heur.PonyStealer.nm1@iunmvabi
NANO-AntivirusTrojan.Win32.Vobfus.lcgli
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan.Blocker.Iflw
EmsisoftGen:Heur.PonyStealer.nm1@iunmvabi (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.49866
VIPREGen:Heur.PonyStealer.nm1@iunmvabi
TrendMicroRansom_Blocker.R002C0DAO24
Trapminemalicious.moderate.ml.score
SophosMal/VBCheMan-A
IkarusTrojan-PWS.Win32.Zbot
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VB.DJ.gen!Eldorado
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Troj.Undef.a
MicrosoftVirTool:Win32/VBInject.TE
XcitiumSuspicious@#ac79ip6he1tg
ArcabitTrojan.PonyStealer.ECDBE8
ZoneAlarmTrojan-Ransom.Win32.Blocker.bpwg
GDataGen:Heur.PonyStealer.nm1@iunmvabi
CynetMalicious (score: 99)
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.2046
PandaGeneric Malware
RisingRansom.Blocker!8.12A (TFE:4:Hxya5UpJBZC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.6140604.susgen
FortinetW32/VBKrypt.CZLQ!tr
AVGWin32:InjectorX-gen [Trj]
Cybereasonmalicious.60a506
DeepInstinctMALICIOUS
alibabacloudRansomware:Win/Blocker.bpwg

How to remove Win32/Injector.AEKN?

Win32/Injector.AEKN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment