Malware

What is “Win32/Injector.ZCL”?

Malware Removal

The Win32/Injector.ZCL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ZCL virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.ZCL?


File Info:

crc32: E231E7C0
md5: d6e7b1007ccba78a0565d839e3e16cab
name: D6E7B1007CCBA78A0565D839E3E16CAB.mlw
sha1: 904e9e2f550f3a6312a6aca8d1c60213e8092fc8
sha256: 13b517891d8e2a032024ee67da23ecc9804c8f7a7fe60ec7b3f15b48d1aca425
sha512: 41c42b5cf24fcb4d60f8b6180c7b75ca8ec5c879f8203e8733aa50398a47a3fdd3a30527c676e6c6ff0dedd8839e8892d63baafa0bf427fb0c236bb81561791f
ssdeep: 3072:elkWvNqr7RJBxIblwtzI9moeAx3Gzr+TIgKJj7aWdm1:elkWvNqHRveieBeIGzr+sZJ3jdm
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Injector.ZCL also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057005b1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.8604
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0057005b1 )
Cybereasonmalicious.07ccba
CyrenW32/Kuluoz.B.gen!Eldorado
SymantecTrojan.Ransomlock!g32
ESET-NOD32a variant of Win32/Injector.ZCL
APEXMalicious
AvastWin32:Crypt-OJD [Trj]
KasperskyUDS:Trojan-Ransom.Win32.Foreign.gen
BitDefenderGen:Variant.Symmi.8604
NANO-AntivirusTrojan.Win32.Carberp.ccjgze
MicroWorld-eScanGen:Variant.Symmi.8604
TencentWin32.Trojan-Spy.Carberp.ddjz
Ad-AwareGen:Variant.Symmi.8604
SophosML/PE-A + Mal/EncPk-AHQ
ComodoTrojWare.Win32.PWS.ZBot.AAA@4sq88d
BitDefenderThetaGen:NN.ZexaF.34088.lGW@aiasWDpi
VIPRETrojan-PWS.Win32.Zbot.aaa (v)
TrendMicroTROJ_RANSOM.SMWX
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
FireEyeGeneric.mg.d6e7b1007ccba78a
EmsisoftGen:Variant.Symmi.8604 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.7453CD
MicrosoftVirTool:Win32/Obfuscator.AEC
GDataGen:Variant.Symmi.8604
AhnLab-V3Spyware/Win32.Zbot.R44715
Acronissuspicious
McAfeePWS-Zbot.gen.arb
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.Foreign
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM.SMWX
RisingTrojan.Generic@ML.100 (RDML:L6518eECk6fR00nnGWk0oQ)
YandexTrojan.Injector!t6+igJbN08w
IkarusTrojan.ATRAPS
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Asprox.B!tr
AVGWin32:Crypt-OJD [Trj]
Qihoo-360Win32/Trojan.Obfuscated.HwQAEpsA

How to remove Win32/Injector.ZCL?

Win32/Injector.ZCL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment