Malware

Win32/Injector.WST (file analysis)

Malware Removal

The Win32/Injector.WST is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.WST virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Injector.WST?


File Info:

name: A869B7F5D69447B2B963.mlw
path: /opt/CAPEv2/storage/binaries/11db94b4cea7b5ad3b14d253ced1f45871ceb117f6dc7c8343697aaec1b1d499
crc32: EA36B549
md5: a869b7f5d69447b2b963bc1bd66697ed
sha1: 17b92097aeec9767256d3a387647e610c01df12d
sha256: 11db94b4cea7b5ad3b14d253ced1f45871ceb117f6dc7c8343697aaec1b1d499
sha512: 3bba64665e0f5f9bb7253e2df8a26ba355abb86ea3c46eaca3f3d827dae3045b6001e0e4d6641ce69aa145f3cd5863b2b2fe754056770016414cd054d1a95a96
ssdeep: 12288:2MVV7uikFgfres2+u/dvNWLzzV7uikFg:2MVlubgfrO/ilubg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BA4AE3E2A95812BF6F6CB71DCE16A87F466B9637D518D4D10D213580C23B93B8E092F
sha3_384: 471dd211fa66fd6d94bf76be8248bf0fd40e578f201eb49c443e3d4169c1be05d96f7c32a2eec76e10a80bc7a14a48e7
ep_bytes: 6878114000e8eeffffff000000000000
timestamp: 2022-01-30 08:45:09

Version Info:

Translation: 0x0409 0x04b0
CompanyName: gioire datelo
FileDescription: case amavi sedavi fato
LegalCopyright: bolli barca tosse 1997
ProductName: ferro
FileVersion: 7.07.0008
ProductVersion: 7.07.0008
InternalName: v4
OriginalFilename: v4.exe

Win32/Injector.WST also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.38811342
FireEyeGeneric.mg.a869b7f5d69447b2
McAfeeRDN/Generic.rp
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001670651 )
AlibabaTrojan:Win32/Injector.4aabbbe6
K7GWTrojan ( 001670651 )
Cybereasonmalicious.7aeec9
BitDefenderThetaGen:NN.ZevbaF.34182.Dm0@aaXVxhjO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.WST
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.VBKrypt.aapak
BitDefenderTrojan.GenericKD.38811342
AvastWin32:InjectorX-gen [Trj]
SophosMal/Generic-S
VIPRELooksLike.Win32.Malware!vb (v)
TrendMicroTROJ_GEN.R06CC0PB522
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.GenericKD.38811342 (B)
IkarusTrojan.Win32.Injector
WebrootW32.Trojan.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.351AF50
MicrosoftTrojan:Script/Phonzy.C!ml
GDataTrojan.GenericKD.38811342
CynetMalicious (score: 100)
VBA32Trojan.Sabsik.FL
ALYacTrojan.GenericKD.38811342
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R06CC0PB522
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/WST!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.139141408.susgen

How to remove Win32/Injector.WST?

Win32/Injector.WST removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment