Malware

How to remove “Win32/Injector.CTAZ”?

Malware Removal

The Win32/Injector.CTAZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CTAZ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Macau)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

salaeigroup.com
ikstrade.co.kr
salesandmarketing101.net
lutheranph.com
dustywinslow.com
lovemydress.pl

How to determine Win32/Injector.CTAZ?


File Info:

crc32: 41D768F8
md5: 404b3f0c2c0b78346f6447509e84fb48
name: 404B3F0C2C0B78346F6447509E84FB48.mlw
sha1: f6db703aac2960274d2a80f22c974fc2f1337d1a
sha256: 0006ff7665159a8ec643a84718446c6314bee441df680ad30912a6aafdc78720
sha512: effe48caa2042df8329cbf4d5c2bf027cb15364e0916d88f974611afb9c263f33c6f7ce250bec73f5ee966a76799fd182fd3586828414ddba1df7943268eb1a0
ssdeep: 6144:3G5iHdAe862qh8tF3T25UOd7XuRmfkAGl13RoUQ5e8yXwSS8VePPehnKvoFwdUl:3G5UdN8Ze2F34UOd7XuRmE73Ron5etg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: Was
FileVersion: 0.214.226.253
CompanyName: Eicon Networks
SpecialBuild: 0.203.154.153
LegalTrademarks: Threshing
Comments: Unites
ProductName: Testes Venerate
ProductVersion: 0.25.245.94
FileDescription: Betray Anguished Summarisers
OriginalFilename: Touchedl.EXE

Win32/Injector.CTAZ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.Bitman.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3981
CynetMalicious (score: 100)
CAT-QuickHealRansom.Teslacrypt.OL4
ALYacTrojan.TeslaCrypt.Gen.4
CylanceUnsafe
ZillyaTrojan.Bitman.Win32.1114
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Bitman.7d39ff1a
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.c2c0b7
BaiduWin32.Trojan.Filecoder.k
SymantecRansom.TeslaCrypt
ESET-NOD32a variant of Win32/Injector.CTAZ
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-1386010
KasperskyTrojan-Ransom.Win32.Bitman.jyc
BitDefenderTrojan.TeslaCrypt.Gen.4
NANO-AntivirusTrojan.Win32.Encoder.eamlsx
ViRobotTrojan.Win32.U.Agent.380928.C
MicroWorld-eScanTrojan.TeslaCrypt.Gen.4
TencentMalware.Win32.Gencirc.10b8e61c
Ad-AwareTrojan.TeslaCrypt.Gen.4
SophosMal/Generic-R + Mal/Ransom-EC
ComodoMalware@#3hpzvx8bmen65
BitDefenderThetaGen:NN.ZexaF.34796.xq0@auC@BPcb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMJ7
McAfee-GW-EditionRansom-Teerac!404B3F0C2C0B
FireEyeGeneric.mg.404b3f0c2c0b7834
EmsisoftTrojan.TeslaCrypt.Gen.4 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Bitman.hv
WebrootTrojan.Telsacrypt
AviraHEUR/AGEN.1111324
Antiy-AVLTrojan/Generic.ASMalwS.1738582
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tescrypt!rfn
GDataTrojan.TeslaCrypt.Gen.4
AhnLab-V3Trojan/Win32.Teslacrypt.R174965
Acronissuspicious
McAfeeRansom-Teerac!404B3F0C2C0B
MAXmalware (ai score=100)
VBA32Hoax.Bitman
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CRYPTESLA.SMJ7
RisingTrojan.Agent!1.A322 (CLASSIC)
YandexTrojan.Bitman!U2ZAo+Qqsu8
IkarusTrojan-Ransom.TeslaCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EOVH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Bitman.HwcBHr4A

How to remove Win32/Injector.CTAZ?

Win32/Injector.CTAZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment