Malware

Should I remove “Win32/Injector.AGBF”?

Malware Removal

The Win32/Injector.AGBF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AGBF virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.AGBF?


File Info:

name: 09198572E73EBFE458D6.mlw
path: /opt/CAPEv2/storage/binaries/337990faf265d70ba660da2fbbe778e334274a7ffe7a99209618216d473b7b4a
crc32: 19988E99
md5: 09198572e73ebfe458d6abc40fc0ad50
sha1: 8633a9471214f2e454680641106a14252a992c4a
sha256: 337990faf265d70ba660da2fbbe778e334274a7ffe7a99209618216d473b7b4a
sha512: 45ed6ff4bfdceafc905a3464ab83d4ceb0d123061abf7e19cae96b53b1d7c40e95989fc23e71e962cb6d3255feb6b3febf88e6394040467613547fc4385afc5d
ssdeep: 6144:xSmblnHpVcIVjygZic2DRkAbCwTMXO7efs9SiQKQTKdbvozpncYUo0JRm+FYReMr:4mb9Hrcc5iDRPWwI+1hQKQTKpvE10J5K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17164121B87694261D80306F5211CFA6EE9B9EF02626613CF73AC0B7FA790095DDB1DE1
sha3_384: 2f6246af15dc6b859454b4ca5630aa6cc266a35ac8c70379c47321e76976ec297b34f4e2900c929ce98c01ce262b6d16
ep_bytes: 6880080000680000000068d4734000e8
timestamp: 1985-02-27 09:55:21

Version Info:

0: [No Data]

Win32/Injector.AGBF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lJ9S
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.16539
FireEyeGeneric.mg.09198572e73ebfe4
Cylanceunsafe
VIPRETrojan.GenericKDZ.16539
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004670ce1 )
AlibabaVirTool:Win32/Injector.eab99c36
K7GWTrojan ( 004670ce1 )
Cybereasonmalicious.2e73eb
VirITTrojan.Win32.Generic.AKCQ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AGBF
TrendMicro-HouseCallTROJ_SPNR.32H513
ClamAVWin.Trojan.16539-3
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.16539
NANO-AntivirusTrojan.Win32.DownLoad3.cqregl
AvastWin32:Cutwail-BM [Trj]
TencentMalware.Win32.Gencirc.10bc0c41
SophosMal/EncPk-AJS
F-SecureTrojan.TR/Spy.Zbot.ajoumea
DrWebTrojan.DownLoad3.8872
ZillyaTrojan.Injector.Win32.198753
TrendMicroTROJ_SPNR.32H513
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.GenericKDZ.16539 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.16539
JiangminTrojan/Generic.axzpm
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Spy.Zbot.ajoumea
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Gimemo
XcitiumTrojWare.Win32.Injector.AGQG@4xjtt3
ArcabitTrojan.Generic.D409B
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Injector.gen!DP
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R65481
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36350.suZ@aKxYA6p
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.Heuristic.1008
PandaTrj/Agent.IVN
APEXMalicious
RisingHackTool.Injector!8.1E2 (TFE:5:suc4E6GLWsV)
IkarusTrojan.Win32.Tobfy
FortinetW32/Zbot.AGWV!tr
AVGWin32:Cutwail-BM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.AGBF?

Win32/Injector.AGBF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment