Malware

Win32/Injector.ANFF removal tips

Malware Removal

The Win32/Injector.ANFF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ANFF virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Injector.ANFF?


File Info:

name: 276A811C5DE74DE3417E.mlw
path: /opt/CAPEv2/storage/binaries/a32304ba74a81b7c4cbaca99aef2ea40c359f47f86b5c430ae21175a32d16452
crc32: A0027C74
md5: 276a811c5de74de3417e904d886583f7
sha1: 424264284d9f5be569deaf3f4fa0dd586b0f6fdf
sha256: a32304ba74a81b7c4cbaca99aef2ea40c359f47f86b5c430ae21175a32d16452
sha512: c0dac8e15b322401d7caca6c83ecc8de2b7b2107ca79a47277448182725618e10fe5071b571b148019920cc1af81593f9a866beb42e7b0ad896919b0901c14ad
ssdeep: 3072:p5ekcskbvq+dBb8CsWp9wxhr5xhjfvR1ZfCPibFAx4odh568pIxN2s34:pAkjkqqspHzhjEPibFW9xOxE64
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB24E067E6914273D0209BBCDC3B9820D22B7C767934946A2BBD3E4B0E792E64C5D317
sha3_384: 104171aceba600456140cafd216865310a86bf280155ad4e5e3c38b34434f4287e6794c13b36eee62909b1116e74379a
ep_bytes: e5171a0b2ccc4386a4002aed661dedf3
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Injector.ANFF also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.283
MicroWorld-eScanTrojan.GenericKD.34626661
FireEyeGeneric.mg.276a811c5de74de3
McAfeeArtemis!276A811C5DE7
MalwarebytesMalware.Heuristic.1003
SangforTrojan.Win32.Wacatac.DA
AlibabaTrojan:Win32/Injector.b05bac92
Cybereasonmalicious.c5de74
ArcabitTrojan.Generic.D2105C65
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.ANFF
Paloaltogeneric.ml
ClamAVWin.Dropper.Dircrypt-9758043-0
BitDefenderTrojan.GenericKD.34626661
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Delf-TTA [Trj]
RisingTrojan.Generic@AI.100 (RDML:mHj7+SM33aEwjcFEVy1Alg)
Ad-AwareTrojan.GenericKD.34626661
SophosML/PE-A + Mal/Dampatch-A
McAfee-GW-EditionBehavesLike.Win32.Playtech.dc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKD.34626661 (B)
IkarusTrojan-Ransom.Mbro
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.34626661
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.C120045
Acronissuspicious
VBA32Trojan.Encoder
ALYacTrojan.GenericKD.34626661
TACHYONTrojan/W32.Banload.226446
APEXMalicious
TencentMalware.Win32.Gencirc.11afc1e7
YandexTrojan.GenAsa!DVOT7J7g604
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.7175209.susgen
FortinetW32/Kryptik.HGEO!tr
AVGWin32:Delf-TTA [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Injector.ANFF?

Win32/Injector.ANFF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment