Malware

Should I remove “Win32:Inject-ATA [Trj]”?

Malware Removal

The Win32:Inject-ATA [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Inject-ATA [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Inject-ATA [Trj]?


File Info:

name: A7CBF07D2C14C8B41646.mlw
path: /opt/CAPEv2/storage/binaries/d7725905de3dcde4567077bb5a92a6e8bc32a64425e677d0448a69e44e80fdef
crc32: C99DB131
md5: a7cbf07d2c14c8b416466932d23662e5
sha1: e8609de905aa9472fac24b47b3c29b88eddc406b
sha256: d7725905de3dcde4567077bb5a92a6e8bc32a64425e677d0448a69e44e80fdef
sha512: cb4ca0c6790aa469c694441dac767185bcb1b5a8600d5571cd3ed1ab158601f7dfbcb1957d9de04e0389a2f90de9d8e14ed581393d41d61c8fef3a0e3ec17efb
ssdeep: 49152:clANaeVha47MqSJcB/9pDEthNBQi9eUfRn:gVeVY47kcxLDEToijRn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19675127EF648971ED4EC08342E86A776167750142E03AA6D59E4337EE9B7F300A71B0B
sha3_384: 1f521c93ae9fb5759ed309498671b146e218fc860c5739d9e7d99ad5b95ecbeccb322e39575cda5bb25be196ff148d05
ep_bytes: 6834164000e8eeffffff000040000000
timestamp: 2011-06-04 21:33:34

Version Info:

Translation: 0x0409 0x04b0
Comments: wwwwwwwwwwwwwwwwwwwwwwww
CompanyName: wwwwwwwwwwwwwwwwwwwwwwww
FileDescription: wwwwwwwwwwwwwwwwwwwwwwww
LegalCopyright: wwwwwwwwwwwwwwwwwwwwwwww
LegalTrademarks: wwwwwwwwwwwwwwwwwwwwwwww
ProductName: wwwwwwwwwwwwwwwwwwwwwwww
FileVersion: 666.777.0066
ProductVersion: 666.777.0066
InternalName: CCC
OriginalFilename: CCC.exe

Win32:Inject-ATA [Trj] also known as:

CyrenCloudW32/Trojan.KAPQ-3498
BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.lfWJ
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.KDV.243086
FireEyeGeneric.mg.a7cbf07d2c14c8b4
SkyhighBehavesLike.Win32.Backdoor.tc
ALYacTrojan.Generic.KDV.243086
Cylanceunsafe
ZillyaBackdoor.Hupigon.Win32.155895
SangforTrojan.Win32.Save.a
K7AntiVirusNetWorm ( 700000151 )
AlibabaWorm:Win32/VBInject.57571377
K7GWNetWorm ( 700000151 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.KDV.D3B58E
BitDefenderThetaAI:Packer.254A2CEF15
VirITTrojan.Win32.Generic.CECI
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.AZR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Vobfus-9813920-0
KasperskyWorm.Win32.VBNA.d
BitDefenderTrojan.Generic.KDV.243086
NANO-AntivirusTrojan.Win32.VB.lxveb
AvastWin32:Inject-ATA [Trj]
TencentWin32.Worm.Vbna.Ximw
Ad-AwareTrojan.Generic.KDV.243086
SophosML/PE-A
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.Pigeon.12660
VIPRETrojan.Generic.KDV.243086
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.KDV.243086 (B)
IkarusBackdoor.Poison
JiangminWorm/VBNA.gzgj
VaristW32/Trojan.KAPQ-3498
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.VBNA
KingsoftWin32.Worm.VBNA.d
XcitiumMalware@#1ec3cc4lkmcry
MicrosoftVirTool:Win32/VBInject.RT
ViRobotWorm.Win32.A.VBNA.372736.B
ZoneAlarmWorm.Win32.VBNA.d
GDataTrojan.Generic.KDV.243086
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R7986
McAfeeGenericRXCP-SU!A7CBF07D2C14
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
RisingHackTool.VBInject!8.1A0 (TFE:3:golCSvZNHTF)
YandexTrojan.GenAsa!zbHgJxJFlxc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2372496.susgen
FortinetW32/VBObfus.C!tr
AVGWin32:Inject-ATA [Trj]
Cybereasonmalicious.905aa9
DeepInstinctMALICIOUS

How to remove Win32:Inject-ATA [Trj]?

Win32:Inject-ATA [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment