Malware

About “Win32/Injector.AMKA” infection

Malware Removal

The Win32/Injector.AMKA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AMKA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/Injector.AMKA?


File Info:

name: 1E587795F8FAFD4FB071.mlw
path: /opt/CAPEv2/storage/binaries/c5c8a38c01ad82ab9067f786613f303c955702ff82fed24e7515849e686a72bb
crc32: ED67D5E8
md5: 1e587795f8fafd4fb071e8ab28ad86db
sha1: e797334dc42542d7e965c65609b920f943d2673d
sha256: c5c8a38c01ad82ab9067f786613f303c955702ff82fed24e7515849e686a72bb
sha512: 0e34ead1ddd6fb0444193fc44a81c139f9bc954d41aa01e33af7477a05514e16519cdea715a16ad812708bfd5353669a20aaedc048080505d44b79484f991a05
ssdeep: 768:om1NTDiZQl2iRh6KMXwGGDMEDyAnMSmlNpk0hJ7vXQsmJQ64F:omXTGulKvYLMPpk0hBXJma6e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194234B2036D29831F332493256F2D6E1197DBC823D75406E73983A695F73EA11A71B3B
sha3_384: 258894aeffaeea0a8d23c865b96ca1b8057e92e007aafad7ef6facdd9392e9c1e9ac330c7035db3e6141f981ef3e8bea
ep_bytes: e8d5130000e989feffff8bff558bec8b
timestamp: 2013-09-09 08:11:06

Version Info:

0: [No Data]

Win32/Injector.AMKA also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.535048
FireEyeGeneric.mg.1e587795f8fafd4f
SkyhighBehavesLike.Win32.Downloader.ph
McAfeePWSZbot-FGA!1E587795F8FA
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00458f421 )
K7GWTrojan ( 00458f421 )
Cybereasonmalicious.5f8faf
BitDefenderThetaAI:Packer.D043ED0E21
VirITTrojan.Win32.Generic.BLQG
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Injector.AMKA
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Variant.Zusy.535048
NANO-AntivirusTrojan.Win32.Fakealert.coogez
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Upatre.hbh
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1320067
DrWebTrojan.Fakealert.42567
VIPREGen:Variant.Zusy.535048
TrendMicroTROJ_UPATRE.SM37
EmsisoftGen:Variant.Zusy.535048 (B)
IkarusTrojan.Win32.Bublik
JiangminTrojan/Bublik.fxn
VaristW32/Trojan.SGRK-5828
AviraHEUR/AGEN.1320067
Antiy-AVLVirus/Win32.Expiro.ropf
Kingsoftmalware.kb.a.995
MicrosoftTrojan:Win32/Guildma.psyU!MTB
XcitiumTrojWare.Win32.Kryptik.BKB@543i9l
ArcabitTrojan.Zusy.D82A08
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataGen:Variant.Zusy.535048
GoogleDetected
AhnLab-V3Trojan/Win.Upatre.C5580658
Acronissuspicious
VBA32SScope.Malware-Cryptor.Ponik
ALYacGen:Variant.Zusy.535048
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!agL3wGTrIKU
SentinelOneStatic AI – Malicious PE
FortinetW32/Small.PRL!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.AMKA?

Win32/Injector.AMKA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment