Malware

Win32/Injector.ZUN removal instruction

Malware Removal

The Win32/Injector.ZUN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ZUN virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.ZUN?


File Info:

crc32: 71122A0F
md5: 73903b79e33d74000ad79b7a3b927062
name: 73903B79E33D74000AD79B7A3B927062.mlw
sha1: bc452d05a9b6b8375d2c3e236180d842786fe154
sha256: 8ec3adc990b2c2e1adb75ac74f8bcda81c4b9ab8bcfaccb0352fd5bdd1889bb8
sha512: e415cc08baa0c251f534b2313a341da3d018abea65f496bfce7141d92299bb5fc4cc629b887466e21b1b470cd8ddd34f920b803900293e4a5c33bef377cfdefd
ssdeep: 24576:4nNx08HD5ohtbgr9KSWyJ8aQKdckOpeDTlvQYkT+tXOr7TQcbA5WYk:4ngq5EfSdaucRYDTlIYkTUQ5gWYk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.ZUN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.9477
CynetMalicious (score: 100)
ALYacGen:Variant.Jacard.120916
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.38740
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.9e33d7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ZUN
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Virus.Blocker-957
KasperskyTrojan-Ransom.Win32.Blocker.spp
BitDefenderGen:Variant.Jacard.120916
NANO-AntivirusTrojan.Win32.Blocker.cufngw
ViRobotTrojan.Win32.A.Blocker.1206272
MicroWorld-eScanGen:Variant.Jacard.120916
TencentTrojan-ransom.Win32.Blocker.kjb
Ad-AwareGen:Variant.Jacard.120916
SophosMal/Generic-S
ComodoMalware@#1m9h6s9xxtv3m
BitDefenderThetaAI:Packer.68042D5919
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.73903b79e33d7400
EmsisoftGen:Variant.Jacard.120916 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126519
eGambitUnsafe.AI_Score_81%
MicrosoftTrojan:Win32/Malagent
ArcabitTrojan.Jacard.D1D854
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Jacard.120916
AhnLab-V3Trojan/Win32.Blocker.R67151
McAfeeGenericR-KGO!73903B79E33D
MAXmalware (ai score=82)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.3963636539
PandaTrj/Genetic.gen
RisingMalware.Undefined!8.C (TFE:dGZlOgSgS+8zmeXwZA)
YandexTrojan.GenAsa!a5DpXfnoP88
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dropper.XUQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwUB2nsA

How to remove Win32/Injector.ZUN?

Win32/Injector.ZUN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment