Malware

What is “Win32/Injector.HTB”?

Malware Removal

The Win32/Injector.HTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.HTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.HTB?


File Info:

crc32: ACF12BE5
md5: ca621937a59cdc959988e736dd3f5055
name: CA621937A59CDC959988E736DD3F5055.mlw
sha1: a6d1a21c1db7143fb66c00dc4e8aa6f4ec9b8680
sha256: 5f372fbfb772c143bcbce5cf819692bc9f8313f557feb6ebf4b91ae9a042e451
sha512: 0d558cdf7a6af18f9a1acec28cd276ff5693e11ef54e90b04c0c19df2ee9cf90a02e1079d1ac4047fa94cca9f14e8f6e9dd880323d88c2345a37e53b834c96cf
ssdeep: 12288:x1aqyQ6IwI2hOrXgetWTwfMmC8dF3QAqSDJeF1oOXCquaa4bgp:TaFhOrwAW8MmC8dKSJcaOXCqBSp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: BO Crack Update Client
FileVersion: 1.626.0069
CompanyName: Crack4Free
ProductName: Crack Black Ops Multiplayer PC
ProductVersion: 1.626.0069
OriginalFilename: BO Crack Update Client.exe

Win32/Injector.HTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.1959
CynetMalicious (score: 100)
ALYacGen:Heur.Spesr.VB.1
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.97381
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Ainslot.147b75bc
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.7a59cd
CyrenW32/VB.DT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.HTB
APEXMalicious
AvastWin32:Spyeye-AJA [Trj]
ClamAVWin.Trojan.Vbkrypt-17855
KasperskyTrojan.Win32.Agent.zocg
BitDefenderGen:Heur.Spesr.VB.1
NANO-AntivirusTrojan.Win32.VBKrypt.eeqdnl
ViRobotTrojan.Win32.A.VBKrypt.540688
MicroWorld-eScanGen:Heur.Spesr.VB.1
TencentWin32.Trojan.Vbkrypt.Szla
Ad-AwareGen:Heur.Spesr.VB.1
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#2vezx9lfpob5f
BitDefenderThetaAI:Packer.BB46B59121
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_VBWrap-1
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.hc
FireEyeGeneric.mg.ca621937a59cdc95
EmsisoftGen:Heur.Spesr.VB.1 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VBKrypt
MicrosoftWorm:Win32/Ainslot.A
ArcabitTrojan.Spesr.VB.1
GDataGen:Heur.Spesr.VB.1
AhnLab-V3Trojan/Win32.Buzus.R26098
McAfeeGenericR-IDW!CA621937A59C
MAXmalware (ai score=100)
VBA32Trojan.Agent
PandaGeneric Malware
TrendMicro-HouseCallMal_VBWrap-1
YandexTrojan.Injector!9GLPpDQCtOY
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Generic.AC.2385FF!tr
AVGWin32:Spyeye-AJA [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.HTB?

Win32/Injector.HTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment