Malware

Win32/Injector.AFPK removal

Malware Removal

The Win32/Injector.AFPK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AFPK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Win32/Injector.AFPK?


File Info:

name: 8E6ECB2A92F5D559A630.mlw
path: /opt/CAPEv2/storage/binaries/bf0b5d25b47a9570a91eebe5ed0e356834a1b38c3c083be18920f94cb4bfb5a8
crc32: 59348262
md5: 8e6ecb2a92f5d559a63076f482d06e99
sha1: 0a29008929f7d6b6f4d7e0f914bf0b70cfb9911d
sha256: bf0b5d25b47a9570a91eebe5ed0e356834a1b38c3c083be18920f94cb4bfb5a8
sha512: 562dc4f8dd4f2bff933ff4c68c1e2c3a612d951f680eb2cf1a5c59df1fdd97d8ebd26bc185057f7a26e443f16e8a4ce40d45991031bdb414a40479c98d69296b
ssdeep: 6144:mDyz87V77777777777777777LbAQYnfARrkuH6cJIQHWcHb7777777777777777S:m35xbawqI6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F364E5D3A20C55E2E4FDED3B5EE16DE9178724537A1B2A7B00E9BA4436187ED40B1E03
sha3_384: 81ca9b541af8c9a2f7acbfc88912ccd657ecb28eecac6f47eb3dfd11a7533c37976756ea8be85e9cc6eaca8d26f394e2
ep_bytes: 6880374000e8f0ffffff000000000000
timestamp: 2013-04-10 10:02:26

Version Info:

Translation: 0x0409 0x04b0
Comments: Do not use this section to promote
CompanyName: Oracle Corporation
LegalTrademarks: An item kept in custody of a third party
ProductName: A specific trade directed towards
FileVersion: 2.02.0012
ProductVersion: 2.02.0012
InternalName: Tipo 99
OriginalFilename: Tipo 99.exe

Win32/Injector.AFPK also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
DrWebTrojan.PWS.Panda.3035
MicroWorld-eScanGen:Trojan.Brresmon.Gen.1
FireEyeGeneric.mg.8e6ecb2a92f5d559
CAT-QuickHealVirTool.VBInject
McAfeePWS-Zbot.gen.arw
CylanceUnsafe
VIPREGen:Trojan.Brresmon.Gen.1
Sangfor[MICROSOFT VISUAL BASIC 5.0]
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/VBInject.de84143a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a92f5d
BitDefenderThetaGen:NN.ZevbaF.34606.um1@a83nXhkG
VirITTrojan.Win32.Panda.EMT
CyrenW32/A-4373a763!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AFPK
APEXMalicious
TrendMicro-HouseCallTROJ_SPNR.30HS13
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-9759638-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Brresmon.Gen.1
NANO-AntivirusTrojan.Win32.Zbot.csfhih
SUPERAntiSpywareTrojan.Agent/Gen-Dorkbot
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114c44d2
Ad-AwareGen:Trojan.Brresmon.Gen.1
EmsisoftGen:Trojan.Brresmon.Gen.1 (B)
ComodoTrojWare.Win32.Zbot.KHJT@4xearo
F-SecureTrojan.TR/Dropper.Gen7
ZillyaTrojan.Zbot.Win32.115643
TrendMicroTROJ_SPNR.30HS13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-EOQ
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Trojan.Brresmon.Gen.1
JiangminTrojan/Generic.awirc
WebrootW32.Infostealer.Zeus
GoogleDetected
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Brresmon.Gen.1
ViRobotTrojan.Win32.Zbot.332800.A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/VBInject
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MDA.140610.X1298
Acronissuspicious
VBA32TrojanSpy.Zbot
MAXmalware (ai score=81)
RisingHackTool.VBInject!8.1A0 (TFE:5:TIqlOlEhKnL)
YandexTrojan.GenAsa!YIYgq4ekis0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dorkbot.BAA!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.AFPK?

Win32/Injector.AFPK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment