Malware

Win32/Injector.QGW removal

Malware Removal

The Win32/Injector.QGW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.QGW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.QGW?


File Info:

name: 5D8898238B58C1C58E7C.mlw
path: /opt/CAPEv2/storage/binaries/c489d2b0e7e405dcb0da08e7a2121e972192937246c7137f664c9e5693fb4920
crc32: 31255F10
md5: 5d8898238b58c1c58e7c84a81acc6c4e
sha1: 4ab051ad8074afc8188d204d8552b3aba4c59e0f
sha256: c489d2b0e7e405dcb0da08e7a2121e972192937246c7137f664c9e5693fb4920
sha512: 56f6936ccf75c179a15a42b0f68640974e5ebcd8c5f87d5476c1a0e2c713e2623270389ae34fa13faf7e215b4bf04d1b4b20c72376445f6c3e24923cccba2c21
ssdeep: 1536:gIMG3XSrVNPLf15tQdonkQo2RS27SBTwiUd5I3oLZiYegq87ju+9Tqfw5jbyPhRB:s/B/QKnkVEj7jdm3+degq87juaTqNPhH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E79302A3E6875211F6A751F45E27039026A61C3FD5F18F0AEA7A7E2BCD75200E0B6473
sha3_384: ebcc21f2b4de873ae1de71d974e898f3b92aaf51118f840df6c1ef6dbff23d20080b5a288e1665403e745732516dfdf8
ep_bytes: 60be005045008dbe00c0faff5789e58d
timestamp: 2012-06-02 16:20:14

Version Info:

Translation: 0x0409 0x04b0
Comments: gaHOfvdfv
CompanyName: xUKZbneg
FileDescription: Cj6OFyg
LegalCopyright: zjDp
LegalTrademarks: RflQCw
ProductName: K5
FileVersion: 10.04.0040
ProductVersion: 10.04.0040
InternalName: Project1
OriginalFilename: Project1.exe

Win32/Injector.QGW also known as:

LionicTrojan.Win32.VB.lALS
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.ManBat.1
FireEyeGen:Heur.ManBat.1
ALYacGen:Heur.ManBat.1
MalwarebytesMalware.Heuristic.1003
VIPREGen:Heur.ManBat.1
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0015e4f01 )
AlibabaWorm:Win32/VBKrypt.8a989d2b
K7GWRiskware ( 0015e4f01 )
Cybereasonmalicious.38b58c
BitDefenderThetaAI:Packer.46917E021F
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Injector.QGW
APEXMalicious
KasperskyTrojan.Win32.VBKrypt.lyqq
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.VBKrypt.fcfrza
AvastWin32:Malware-gen
TencentWin32.Trojan.Vbkrypt.Yylw
SophosMal/Generic-R
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.VbCrypt.8
ZillyaTrojan.VBKrypt.Win32.166085
TrendMicroTROJ_GEN.R03BC0GJJ21
McAfee-GW-EditionBehavesLike.Win32.Pluto.mc
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.ManBat.1 (B)
IkarusTrojan.Win32.VBKrypt
GDataGen:Heur.ManBat.1
JiangminTrojan.VBKrypt.edtr
Webrootw32.malware.gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.VBKrypt
XcitiumMalware@#15oavcd4uzpv9
ArcabitTrojan.ManBat.1
ZoneAlarmTrojan.Win32.VBKrypt.lyqq
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!5D8898238B58
VBA32BScope.Trojan.VBKrypt
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0GJJ21
RisingWorm.Autorun!8.50 (CLOUD)
YandexTrojan.Injector!D1cW7lakaWo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74809593.susgen
FortinetW32/Refroso.AGEA!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Injector.QGW?

Win32/Injector.QGW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment