Malware

Win32/Injector.VTQ removal tips

Malware Removal

The Win32/Injector.VTQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.VTQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.VTQ?


File Info:

crc32: 51E1AD2F
md5: ba4f75662517ae9faac7e6257c8cd8e8
name: BA4F75662517AE9FAAC7E6257C8CD8E8.mlw
sha1: fe0e876f3e62bf52566b871a9ce5ebc1f27a92fe
sha256: 1de5831c6f5d6e78007d4b2218853e439af5768dd1830bc3ee7a3ed7bf40345f
sha512: ad3ea00ec8b1f64f67ac981ae649fb5877b0e48bfe5693e4a9f4d5a43662e504c000c03ea5d5e99a935e22170bde57049296e30e8264bb6781f2bc8323170c01
ssdeep: 12288:NyuPEEyGBHidErWSSlyOj7oBc3M4xqNT0IYGqnIYsSPsawjFXGduXDFIcJX7E:MsOGBDMxwsM4xqNT0IYGaIBSPsnGATJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009-2011 Oracle Corporation
InternalName: VirtualBox
FileVersion: 4.0.12.72916
CompanyName: Oracle Corporation
ProductName: Oracle VM VirtualBox
ProductVersion: 4.0.12.r72916
FileDescription: VirtualBox
OriginalFilename: VirtualBox.exe
Translation: 0x0409 0x04b0

Win32/Injector.VTQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0040df0e1 )
LionicTrojan.Win32.DarkKomet.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Um0@dicPqgnm
CylanceUnsafe
ZillyaTrojan.Genome.Win32.249161
K7GWTrojan ( 0040df0e1 )
Cybereasonmalicious.62517a
CyrenW32/Kryptik.ATC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.VTQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.DarkKomet.hxni
BitDefenderGen:Heur.PonyStealer.Um0@dicPqgnm
NANO-AntivirusTrojan.Win32.TrjGen.bnkvfp
MicroWorld-eScanGen:Heur.PonyStealer.Um0@dicPqgnm
TencentWin32.Trojan.Genome.csol
Ad-AwareGen:Heur.PonyStealer.Um0@dicPqgnm
SophosML/PE-A + Mal/VBInj-Y
ComodoTrojWare.Win32.Injector.XFR@4rorse
BitDefenderThetaGen:NN.ZevbaF.34266.Um0@aicPqgnm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.ba4f75662517ae9f
EmsisoftGen:Heur.PonyStealer.Um0@dicPqgnm (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Downloader.Gen
AviraTR/Dropper.VB.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.5695B9
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Heur.PonyStealer.Um0@dicPqgnm
AhnLab-V3Trojan/Win32.Injector.C2371713
McAfeePWS-Zbot.gen.asg
MAXmalware (ai score=88)
VBA32BScope.Worm.WBNA
PandaGeneric Malware
YandexTrojan.GenAsa!UtKaxKcb1Q0
IkarusTrojan.Dropper
FortinetW32/VBKrypt.MBSX!tr
AVGWin32:Malware-gen

How to remove Win32/Injector.VTQ?

Win32/Injector.VTQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment