Malware

About “Win32:Injecter-AT [Trj]” infection

Malware Removal

The Win32:Injecter-AT [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Injecter-AT [Trj] virus can do?

  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

hq-pharma.org

How to determine Win32:Injecter-AT [Trj]?


File Info:

crc32: F4F0F156
md5: 76ea364ca7b79dbf293f5a8b60452613
name: 76EA364CA7B79DBF293F5A8B60452613.mlw
sha1: 5b041c600f240d613f010a75fec7de48f78df6ff
sha256: 7551504440b3444004a2ae62bbae92c6ac9f5736630c586560c0f24a9ed0b51a
sha512: 35a7792c2d6a4ccbce3795cec86b088778a56b52d6a078b90f6567cc01dbc92f7d4b2d60cbf0d0f5468f17e724e73dc3c6e07de3c40b455f538bb0c330a9c024
ssdeep: 24576:g8eeqsaw4LLqAe0q0Lvou8txzu4uBvu9FX:teeqsawkLqAePCIVu4uBvu9FX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:Injecter-AT [Trj] also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.FireOn.5
MicroWorld-eScanTrojan.Downloader.Small.AAKR
FireEyeGeneric.mg.76ea364ca7b79dbf
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeBackDoor-DRW
CylanceUnsafe
VIPREWorm.Win32.Socks.bt (fs)
AegisLabTrojan.Win32.Agent.tqXm
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056ccdc1 )
BitDefenderTrojan.Downloader.Small.AAKR
K7GWTrojan-Downloader ( 0056ccdc1 )
Cybereasonmalicious.ca7b79
BitDefenderThetaAI:Packer.4E98D6F31B
CyrenW32/Socks.A.gen!Eldorado
SymantecW32.Mandaph
TotalDefenseWin32/Korced!generic
TrendMicro-HouseCallBKDR_SMALL.JAN
Paloaltogeneric.ml
ClamAVWin.Worm.Socks-9
KasperskyTrojan-Downloader.Win32.Agent.kiz
AlibabaTrojanDownloader:Win32/Autorun.c0a5c519
NANO-AntivirusTrojan.Win32.Agent.dabszn
RisingWorm.Autorun!8.50 (TFE:dGZlOgVOcCd2ih4ggg)
Ad-AwareTrojan.Downloader.Small.AAKR
SophosML/PE-A + Mal/Koceg-A
ComodoTrojWare.Win32.TrojanDownloader.Small.OCE@dd2e
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan-Downloader.Agent.au
ZillyaDownloader.Agent.Win32.42350
TrendMicroBKDR_SMALL.JAN
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
EmsisoftTrojan.Downloader.Small.AAKR (B)
IkarusTrojan-Downloader.Win32.Small
JiangminWorm/AutoRun.gxl
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Downloader]/Win32.Agent
MicrosoftWorm:Win32/Autorun.gen!BS
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Downloader.Small.AAKR
ViRobotTrojan.Win32.Downloader.294623
ZoneAlarmTrojan-Downloader.Win32.Agent.kiz
GDataTrojan.Downloader.Small.AAKR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R122920
Acronissuspicious
VBA32BScope.Trojan.Click
ALYacTrojan.Downloader.Small.AAKR
TACHYONTrojan-Downloader/W32.ZBot.Zen
MalwarebytesGeneric.Worm.Autorun.DDS
PandaW32/Socks.A.worm
APEXMalicious
ESET-NOD32Win32/TrojanDownloader.Small.OCE
TencentMalware.Win32.Gencirc.10b07944
YandexTrojan.GenAsa!w57yFDP7Hyw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Socks.NAL!tr
AVGWin32:Injecter-AT [Trj]
AvastWin32:Injecter-AT [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/TrojanDownloader.Small.HwcBEIcA

How to remove Win32:Injecter-AT [Trj]?

Win32:Injecter-AT [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment