Malware

About “Win32/Injector.FLQ” infection

Malware Removal

The Win32/Injector.FLQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.FLQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.FLQ?


File Info:

name: 0BD8D936A224E19EB499.mlw
path: /opt/CAPEv2/storage/binaries/55e65880eaae83b7bef2b65783bb950c44c5497397ca96d05cafafa409559ba4
crc32: 9A1B6576
md5: 0bd8d936a224e19eb4990fdd2f7bbad8
sha1: 8ba019a11691dec67c7dfea0117327cea74fb016
sha256: 55e65880eaae83b7bef2b65783bb950c44c5497397ca96d05cafafa409559ba4
sha512: edcdc1a558af6ca706509206aed1d4aa38a88509370a9d1898fba2360560fa41f75507447fc399d7c19ed2008314c09e39d477cb5eaf8f3e6a39aa58ab71d15a
ssdeep: 6144:UjEyz0/MzKSByxjw7XxzDJrX7W8t7Mde+nlZj6nqy3d9CaQ4ppFMwJNDreoIJap2:UjEpYxzDJXA0+nzNaQ4ppdJN9IJap2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110F4F1143F85C833D69211B8D9A1C370EAB89D813B36CA83BBD92D7FBF352C15955286
sha3_384: 43d058229a5fbac888a703288a9e0529002dbff49c983a067838b6ed4f7fa7354d717be1b0cfd06395794f0a7313e327
ep_bytes: e890440000e978feffff8bff558bec8b
timestamp: 2011-03-23 19:29:06

Version Info:

FileDescription: Java(TM) Platform SE binary
FileVersion: 2,8,0,0
InternalName: Java(TM)
LegalCopyright: Copyright© 1995, 2010, Oracle and/or its affiliates. All rights reserved.
OriginalFilename: Runescape auto switcher.exe
ProductName: Java(TM)
ProductVersion: 2.8.0.0
Translation: 0x0409 0x04b0

Win32/Injector.FLQ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.IPZ.3
FireEyeGeneric.mg.0bd8d936a224e19e
SkyhighBehavesLike.Win32.Emotet.bm
McAfeeArtemis!0BD8D936A224
Cylanceunsafe
ZillyaTrojan.Cosmu.Win32.7690
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Injector.19c7eafd
BitDefenderThetaGen:NN.ZexaF.36802.Uu0@aOLKV6ii
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.FLQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.IPZ.3
NANO-AntivirusTrojan.Win32.Bybz.byepe
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.13b1e27e
EmsisoftGen:Heur.IPZ.3 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebWin32.HLLW.Autoruner.47443
VIPREGen:Heur.IPZ.3
SophosMal/Generic-S
JiangminTrojan/Llac.cir
WebrootW32.Coinminer.Gen
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Kryptik.ujy
Kingsoftmalware.kb.a.986
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumSuspicious@#2luhuk0pb56ga
ArcabitTrojan.IPZ.3
ViRobotWorm.Win32.A.Shakblades.247298
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.IPZ.3
CynetMalicious (score: 100)
VBA32OScope.Worm.Bybz.31321
GoogleDetected
MAXmalware (ai score=98)
PandaTrj/Genetic.gen
RisingTrojan.Agent!8.B1E (TFE:5:kfny89htEaB)
YandexTrojan.GenAsa!R5guZHhVir0
IkarusWorm.Win32.Bybz
MaxSecureTrojan.Malware.1920352.susgen
FortinetW32/Scar.SMT!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/IPZ

How to remove Win32/Injector.FLQ?

Win32/Injector.FLQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment