Trojan

About “Trojan.Win32.Injuke.fhbv” infection

Malware Removal

The Trojan.Win32.Injuke.fhbv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Injuke.fhbv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.Win32.Injuke.fhbv?


File Info:

name: 32A03160AFE3642AE4A2.mlw
path: /opt/CAPEv2/storage/binaries/2af341a187dcb5fa35f39d6a5bbe3e4b70555007f38b7954a843b0a1571fdbde
crc32: 74480F0D
md5: 32a03160afe3642ae4a29116cd08af72
sha1: b3850775ad4f37802005bf675b76cb33e21ac48f
sha256: 2af341a187dcb5fa35f39d6a5bbe3e4b70555007f38b7954a843b0a1571fdbde
sha512: e7d49d2ea85e49c35e92f385f54177f491853024d6bc37174f82313912767fee6c0eca6b891fc8b944a5069c9340db2b83d89f3eab698786a3afb641ab487eec
ssdeep: 3072:QYKAk5Lm+CeJme0fGVUcZeiPWrxpzbgqruPhsJVggjcGkNIVqIq5wu8:QUqT9JMGVdeiPuzbgwuyr7ITsqQu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115549EF175A8D832C4A36A354460BAD55E3BFD12D520818B3234379E5F32ECC5AE635E
sha3_384: 166c295fc58eba43994868447a75ad2663c14563464cdbb04ac755cfc3e42c3318cf83d3421ea612b4557c5ebdaedd99
ep_bytes: e8e0330000e978feffffcccccccccccc
timestamp: 2020-11-11 03:21:31

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.70.77
Translation: 0x0129 0x0794

Trojan.Win32.Injuke.fhbv also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Injuke.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38453019
FireEyeGeneric.mg.32a03160afe3642a
CAT-QuickHealTrojan.Injuke
McAfeePacked-GEE!32A03160AFE3
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Injuke.05189312
K7GWTrojan ( 0058ca411 )
K7AntiVirusTrojan ( 0058ca411 )
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNWZ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tofsee-9919472-0
KasperskyTrojan.Win32.Injuke.fhbv
BitDefenderTrojan.GenericKD.38453019
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan.Injuke.Ljka
Ad-AwareTrojan.GenericKD.38453019
EmsisoftTrojan.GenericKD.38453019 (B)
DrWebTrojan.Siggen16.26223
TrendMicroTROJ_FRS.0NA103A622
McAfee-GW-EditionBehavesLike.Win32.Packed.dm
SophosMal/Generic-R + Mal/Agent-AWV
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.BSE.IJTJXK
JiangminExploit.ShellCode.geb
WebrootW32.Trojan.Gen
AviraTR/AD.MalwareCrypter.mxffz
KingsoftWin32.Troj.Injuke.fh.(kcloud)
ArcabitTrojan.Generic.D24ABF1B
MicrosoftRansom:Win32/StopCrypt.MZE!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R462691
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.suW@aaxBJodK
ALYacTrojan.GenericKD.38453019
MAXmalware (ai score=82)
VBA32BScope.TrojanSpy.Convagent
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_FRS.0NA103A622
RisingExploit.ShellCode!8.2A (CLOUD)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.5ad4f3
PandaTrj/GdSda.A

How to remove Trojan.Win32.Injuke.fhbv?

Trojan.Win32.Injuke.fhbv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment