Threat Database Trojans Trojan.Injector.NA

Trojan.Injector.NA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 401
First Seen: January 16, 2013
Last Seen: January 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Injector.NA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to infiltrate your computer and cause harm, making it essential to understand its nature and take steps to remove it. In this report, we will provide an overview of Trojan.Injector.NA, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.Injector.NA?

Trojan.Injector.NA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.Injector.NA" suggests that it is a Trojan-type threat, but without more specific information, it's difficult to determine its exact nature or the family it belongs to. Trojans are known for their ability to sneak into systems by masquerading as useful applications, only to unleash their malicious payload once installed.

How Trojan.Injector.NA Operates

Generally, Trojan horses like Trojan.Injector.NA operate by exploiting vulnerabilities in software or tricking users into installing them. Once inside a system, they can perform a variety of malicious actions, including but not limited to, stealing sensitive information, installing additional malware, or providing unauthorized access to the infected computer. The specific operations of Trojan.Injector.NA would depend on its design and the intentions of its creators, but like other Trojans, it is likely designed to remain hidden while it carries out its malicious activities.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, depending on the malware's purpose. Common signs include unexpected changes to computer settings, slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. In some cases, the infection may not exhibit obvious symptoms, making it difficult for users to detect without the aid of security software. If you suspect that your computer is infected with Trojan.Injector.NA, it's crucial to take immediate action to mitigate any potential damage.

How to Remove Trojan.Injector.NA

  1. Enter Safe Mode with Networking to prevent the malware from spreading or interfering with the removal process. This mode allows you to use the internet to download necessary tools while limiting the malware's ability to run.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time you suspect the infection occurred. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and then run another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Injector.NA from your system requires careful and immediate action. By following the steps outlined above and maintaining vigilance in your computing practices, you can help protect your system from future infections. Remember, prevention is key, so always be cautious when downloading software, avoid suspicious links, and keep your security software up to date. If you are unsure about any part of the removal process, consider seeking help from a professional to ensure your system is thoroughly cleaned and secured.

Analysis Report

General information

Family Name: Trojan.Injector.NA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 9d0bf4504f855140bbd6f4eca2f97f2d
SHA1: 1d775565defa32d5b3b2d00c74c156578b8b31f4
SHA256: 0E549137BAA62344B7F9BD6B095593E31B86611527AE797F8F64C80C28FDCB6B
File Size: 18.43 KB, 18432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • packed
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 182
Potentially Malicious Blocks: 38
Whitelisted Blocks: 144
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 x x x x x 0 0 x 0 x x x x x x x 0 x 0 x x 0 0 x x x x x 0 x 0 x x x x x x x x 0 x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\roaming\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��7 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee)Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k 8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::windows security notifier C:\Users\Ionyzqkm\AppData\Roaming\svchost.exe RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecute
Network Winsock
  • gethostbyname
  • inet_addr
  • send
  • socket

Shell Command Execution

C:\Users\Ionyzqkm\AppData\Roaming\svchost.exe "C:\Users\Ionyzqkm\AppData\Roaming\svchost.exe"
open C:\Users\Ionyzqkm\AppData\Roaming\svchost.exe

Trending

Most Viewed

Loading...