Malware

Win32/Injector.AIXF removal tips

Malware Removal

The Win32/Injector.AIXF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AIXF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.AIXF?


File Info:

crc32: 9DF26AF7
md5: e8c495e7e200cfc71dc392b44a6ae0fa
name: E8C495E7E200CFC71DC392B44A6AE0FA.mlw
sha1: 6476d0302ae5fb82bb7ff5250afedd025e2d395b
sha256: 9d9d2833661bbcab305ca1727b3358e9187e41d3942ae022e58fcbdccd5cb348
sha512: 72f3882d7af7b88f7ebcdff3d2caa7f31c98cd3bdbe699ec3c9091dce21996c97d6b3f9deec9b01b002de53648b04d9bac5bf852cb6f21740038dcc699d100d7
ssdeep: 3072:AGbgjsbb/l3HnwpE8S9MCn9Op3Um4154LBw120rOwMCO1fv7UiO2a1:jgjsbbl3HnufS9MsokYhwMCO1YqQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: TWENTYTHREETHREE
FileVersion: 1.00
CompanyName: Microsoft
ProductName: TWENTYTHREETHREE
ProductVersion: 1.00
OriginalFilename: TWENTYTHREETHREE.exe

Win32/Injector.AIXF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.547
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.PEF13C.Win32.540
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.7e200c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AIXF
APEXMalicious
AvastWin32:GenMalicious-JAJ [Trj]
ClamAVWin.Malware.Zusy-7082349-0
KasperskyTrojan-Spy.Win32.Zbot.vkri
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Zbot.ezeahv
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentMalware.Win32.Gencirc.10c8c3b0
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Troj/Zbot-FPF
BitDefenderThetaGen:NN.ZevbaF.34690.nm1@aChWWVhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dc
FireEyeGeneric.mg.e8c495e7e200cfc7
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.fsiy
AviraTR/Dropper.VB.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2F035E
MicrosoftPWS:Win32/Zbot
AegisLabTrojan.Win32.Zbot.l!c
GDataTrojan.Ransom.Cerber.1
TACHYONTrojan-Spy/W32.VB-ZBot.213504.B
AhnLab-V3Trojan/Win32.Zbot.R73149
McAfeePWS-Zbot.gen.oj
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
PandaTrj/Genetic.gen
RisingMalware.Zbot!8.E95E (TFE:3:sVGAFAl3UbO)
YandexTrojan.GenAsa!fjWi2sRG2oE
IkarusWorm.Win32.Dorkbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKryptik.YZ!tr
AVGWin32:GenMalicious-JAJ [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.AIXF?

Win32/Injector.AIXF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment