Worm

Worm:Win32/Ainslot removal

Malware Removal

The Worm:Win32/Ainslot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ainslot virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine Worm:Win32/Ainslot?


File Info:

crc32: 1E0D0F1E
md5: a4cfc23d418fd8b54474a55685c9c9a2
name: injector.exe
sha1: ddac5751d2b6aee3ff8c11ca35ac5abdff2ee4bf
sha256: 6c5012282836268ebca8355f27bee3101bcc6c52358d1838b447e7902f9b6a1b
sha512: ec085de3212698dcdee486773c19a5b058ccd54d0874d1b03971e32e3d8d6558206788533d2fddfe723116b6aaa798468b438efac9d57b4fa723e962833829f0
ssdeep: 24576:Fes4MROxnFj30xXFHXRrZlI0AilFEvxHiSG:Fe/Mi1sRhrZlI0AilFEvxHi
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Loader.exe
FileVersion: 1.10.19.10
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.11.20.11
FileDescription: x42dx442x43e loader x43ax43ex442x440x43ex439 x438x43dx434x436x435x43ax442x438x442 x447x438x442 x432 dll x430x440x445x438x432x435.
OriginalFilename: Orcus.exe

Worm:Win32/Ainslot also known as:

DrWebTrojan.DownLoader25.14206
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.1196C345
FireEyeGeneric.mg.a4cfc23d418fd8b5
CAT-QuickHealTrojan.MsilFC.S6051223
McAfeeBackDoor-FDJE!A4CFC23D418F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005011a81 )
BitDefenderGeneric.MSIL.PasswordStealerA.1196C345
K7GWTrojan ( 005011a81 )
Cybereasonmalicious.d418fd
TrendMicroBKDR_ORCUSRAT.SM
BitDefenderThetaGen:NN.ZemsilF.34132.4m0@ayvGieg
CyrenW32/MSIL_Injector.KK.gen!Eldorado
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
GDataMSIL.Backdoor.Orcus.A
KasperskyHEUR:Trojan-Spy.MSIL.Generic
Ad-AwareGeneric.MSIL.PasswordStealerA.1196C345
SophosTroj/Orcusrot-A
ComodoTrojWare.MSIL.Orcusrat.D@8ftc87
F-SecureHeuristic.HEUR/AGEN.1128549
Invinceaheuristic
Trapminemalicious.moderate.ml.score
EmsisoftGeneric.MSIL.PasswordStealerA.1196C345 (B)
IkarusTrojan.MSIL.Agent
F-ProtW32/MSIL_Injector.KK.gen!Eldorado
JiangminTrojan.Generic.awmpo
AviraHEUR/AGEN.1128549
Endgamemalicious (high confidence)
ArcabitGeneric.MSIL.PasswordStealerA.1196C345
ZoneAlarmHEUR:Trojan-Spy.MSIL.Generic
MicrosoftWorm:Win32/Ainslot
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/OrcusRAT.Exp
VBA32Trojan.Downloader
ALYacGeneric.MSIL.PasswordStealerA.1196C345
MAXmalware (ai score=88)
MalwarebytesBackdoor.Orcus
ESET-NOD32a variant of MSIL/Orcusrat.D
TrendMicro-HouseCallBKDR_ORCUSRAT.SM
RisingBackdoor.Orcus!8.A4F3 (TFE:dGZlOgzkeJGdb2VWzg)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Generic.AP.F529E!tr
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.755B.Malware.Gen

How to remove Worm:Win32/Ainslot?

Worm:Win32/Ainslot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment