Malware

How to remove “Win32/Injector.OEA”?

Malware Removal

The Win32/Injector.OEA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.OEA virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Injector.OEA?


File Info:

name: 45B583D58C21A53A49A3.mlw
path: /opt/CAPEv2/storage/binaries/c9e6a7dd1735b01180b0b96cfa8bcffb4499f299f705302b8dd6f1fb1d5404ed
crc32: 2DF84585
md5: 45b583d58c21a53a49a3961729f1b4c9
sha1: 7a371289551f21e246c29cf57b1714a02d79cd18
sha256: c9e6a7dd1735b01180b0b96cfa8bcffb4499f299f705302b8dd6f1fb1d5404ed
sha512: 0bc8f031e22b4326c09fdf8442e3cd05eb62cee7e09d24c5460a76287e1a7f759989eae0e3fe31084641f5cbc7ea528ddbedd609141893d179b6aa16be9c1329
ssdeep: 3072:JDsq11CalT8cq+0lwe3gEukyB0cUDgLUckINDkB0ZxMcpkdR7A05YPfcUPu:W4cDcq+0PYBXUDgZZNuAecpko0MPu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F041270A9815236D8A5DC700264BAE7D73FFA00EAB050935A117AB91B7F3D51D7B30E
sha3_384: 17d453bfdd5c3bcc6024bfb5a88539cb4f40de0a23890f263e159713ee3187c3c44fefb7f86000ef3a76345b0d7cbc70
ep_bytes: 6a606890624000e856040000bf940000
timestamp: 2012-02-17 13:53:30

Version Info:

0: [No Data]

Win32/Injector.OEA also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ProcessHijack.lqZ@aqZ@sdlc
ALYacGen:Trojan.ProcessHijack.lqZ@aqZ@sdlc
CylanceUnsafe
SangforARMADILLO17
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Injector.d5793f6e
K7GWTrojan ( 004caaf01 )
K7AntiVirusTrojan ( 004caaf01 )
VirITTrojan.Win32.Injector.CSXX
CyrenW32/Zbot.EE.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.OEA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-29154
KasperskyTrojan-Spy.Win32.Zbot.dmvl
BitDefenderGen:Trojan.ProcessHijack.lqZ@aqZ@sdlc
NANO-AntivirusTrojan.Win32.Zbot.crargi
AvastWin32:Trojan-gen
RisingTrojan.Generic@AI.88 (RDML:ACLkshR7WYyHXwzJSTCqVg)
Ad-AwareGen:Trojan.ProcessHijack.lqZ@aqZ@sdlc
SophosMal/Generic-R + Mal/FakeAV-QN
ComodoTrojWare.Win32.Spy.Zbot.DTNY@4pp6dp
DrWebTrojan.PWS.Panda.547
ZillyaTrojan.Buzus.Win32.96379
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.45b583d58c21a53a
EmsisoftGen:Trojan.ProcessHijack.lqZ@aqZ@sdlc (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ProcessHijack.lqZ@aqZ@sdlc
JiangminTrojan/Buzus.beld
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
KingsoftWin32.Heur.KVMH017.a.(kcloud)
ArcabitTrojan.ProcessHijack.EE08B0
ViRobotTrojan.Win32.A.Buzus.188441
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R22054
McAfeePWS-Zbot.gen.su
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesMachineLearning/Anomalous.100%
TencentMalware.Win32.Gencirc.11490cde
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.3646200.susgen
FortinetW32/Injector.SUU!tr
BitDefenderThetaGen:NN.ZexaF.34712.lqZ@aqZ@sdlc
AVGWin32:Trojan-gen
Cybereasonmalicious.58c21a
PandaTrj/Genetic.gen

How to remove Win32/Injector.OEA?

Win32/Injector.OEA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment