Malware

Win32/Injector.QLW malicious file

Malware Removal

The Win32/Injector.QLW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.QLW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.QLW?


File Info:

crc32: 468ABB05
md5: ea7f0458925a99ce05d8d38a887938db
name: EA7F0458925A99CE05D8D38A887938DB.mlw
sha1: b21925a23d24eda566cf77c29a12250a0f0395a4
sha256: a0159bb2f97957ab1934901edf1a2cc5ff2bae980348e1946d658bcf4377aa0f
sha512: 5c2a20da2a94a14029066d1f8074d4447974f254b5a1f03b6569fb5eb5f19339cb08088cf3d40097e1e533d46505a226cb994b3a32888f97dc95ec648362371d
ssdeep: 3072:xO4I3W8Ph7YPKt9jY5GFdF81jhweX4TILFhEIVc:B5h1Fw84cLFe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: EfXzOq
FileVersion: 8.00.0013
CompanyName: QWpwm
LegalTrademarks: ZLae
ProductName: HDPf
ProductVersion: 8.00.0013
OriginalFilename: EfXzOq.exe

Win32/Injector.QLW also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004d4a2d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.5908
CynetMalicious (score: 100)
ALYacGen:Heur.ManBat.1
CylanceUnsafe
ZillyaTrojan.MBRlock.Win32.421
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/HmBlocker.94c98c5a
K7GWTrojan ( 004d4a2d1 )
Cybereasonmalicious.8925a9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.QLW
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.HmBlocker.nxog
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.HmBlocker.eibsmx
MicroWorld-eScanGen:Heur.ManBat.1
TencentWin32.Trojan.Hmblocker.Alsp
Ad-AwareGen:Heur.ManBat.1
SophosML/PE-A + Mal/VB-ADS
BitDefenderThetaGen:NN.ZevbaF.34690.hm0@a8Q27!di
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Trojan.cm
FireEyeGeneric.mg.ea7f0458925a99ce
EmsisoftGen:Heur.ManBat.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.HmBlocker.m
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.ACB766
MicrosoftTrojan:Win32/Dynamer!ac
AegisLabTrojan.Win32.HmBlocker.j!c
GDataGen:Heur.ManBat.1
TACHYONRansom/W32.VB-HmBlocker.130048
McAfeeArtemis!EA7F0458925A
MAXmalware (ai score=100)
VBA32BScope.Trojan-Ransom.Winlock.2741
PandaTrj/CI.A
RisingRansom.HmBlocker!8.2A63 (CLOUD)
YandexTrojan.GenAsa!9D8KYEbAqXg
IkarusTrojan-Ransom.Gimemo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.IKK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.QLW?

Win32/Injector.QLW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment