Malware

About “Win32/Injector.RUL” infection

Malware Removal

The Win32/Injector.RUL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.RUL virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.RUL?


File Info:

crc32: 8C0E0435
md5: 29a086ab3fc166d5c38881f333b71606
name: 29A086AB3FC166D5C38881F333B71606.mlw
sha1: d74cbbb2e47e961933d79aa2db3bc6f45414a99a
sha256: 617e4184341df60afef09d7a36787da5c495a30729934e55102088843322df60
sha512: 30079b1b344d1ea952ef31c9388ee11c43b00bc052e561d061f60b64c60dd7074776f83d8f5354d75e330566d462b14992bd5f0914c5270aa221df5e7fc35d8f
ssdeep: 3072:rMKdJ6dCHofAVTsRnQ67mujdBrcW6Eb+Mj9:rJ6sIfAG9Ra
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.RUL also known as:

K7AntiVirusTrojan ( 0055e3991 )
DrWebTrojan.MBRlock.30
ALYacGen:Variant.Fugrafa.110944
CylanceUnsafe
ZillyaTrojan.Mbro.Win32.544
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Genasom.363d8d79
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.b3fc16
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.RUL
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Mbro-67
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Fugrafa.110944
NANO-AntivirusTrojan.Win32.MBRlock.rqabq
ViRobotTrojan.Win32.A.Mbro.107520
MicroWorld-eScanGen:Variant.Fugrafa.110944
TencentWin32.Trojan.Ransom.Htci
Ad-AwareGen:Variant.Fugrafa.110944
SophosMal/Delf-DV
ComodoTrojWare.Win32.Spy.Zbot.SD@4omzpz
BitDefenderThetaAI:Packer.2453B1CE21
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot.gen.bfj
FireEyeGeneric.mg.29a086ab3fc166d5
EmsisoftGen:Variant.Fugrafa.110944 (B)
JiangminTrojan/MBro.ny
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.52435A
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom.JJ
ZoneAlarmTrojan-Ransom.Boot.Mbro.d
GDataGen:Variant.Fugrafa.110944
AhnLab-V3Malware/Win32.Generic.C2321193
McAfeePWS-Zbot.gen.bfj
MAXmalware (ai score=100)
VBA32Hoax.MBro
PandaTrj/Pacrypt.E
RisingTrojan.Generic@ML.94 (RDML:pQgq9le/B/t7RfyGwUj4Qg)
YandexTrojan.GenAsa!r541yDDJInI
IkarusTrojan-Ransom.Mbro
MaxSecureTrojan.Malware.4027611.susgen
FortinetW32/Zbot.ZY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.RUL?

Win32/Injector.RUL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment