Malware

Win32/Injector.BDES removal instruction

Malware Removal

The Win32/Injector.BDES is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BDES virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Injector.BDES?


File Info:

name: C4E911DC9C6B14246C4F.mlw
path: /opt/CAPEv2/storage/binaries/56b05c514b22d9e9a83d3bf750f4b8fe3b67d33a3e8adc56436a454e531317ae
crc32: F4C9F8CC
md5: c4e911dc9c6b14246c4fe8767c9ee617
sha1: 0ace579a4d44b1eb85740df6a0881595c9a22940
sha256: 56b05c514b22d9e9a83d3bf750f4b8fe3b67d33a3e8adc56436a454e531317ae
sha512: 57282c3894d0fbaa833c2dac0a0679be4d143247f8118756b9f643668a67c4b0d9a1822b38fde0afb9d000c74d1da20969c542f47e8610ddad913ee61b73cff2
ssdeep: 6144:R3+31PlbLNsv1i8HRussh95RBQsDLXHkUAmvi69uc5/K7/zLL98Gwy:dRv1iW5C5XQsfHkUAmqy/WLmy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5B49D90E246DCE9E41572F19C2AD97011A7AD9EA8B00A2F317DB21D15B3363DCA3D1F
sha3_384: 8ed3253495cdffecdafcd899befc0be51a5ca730447f55eb2e7f2307df09172b5b440716fb3e22003b14015e929d6b7f
ep_bytes: 558bec6aff68286e400068de4a400064
timestamp: 2014-05-05 19:00:21

Version Info:

Comments:
CompanyName:
FileDescription: cluster
FileVersion: 1, 0, 0, 1
InternalName: cluster
LegalCopyright: Copyright ? 2014
LegalTrademarks:
OriginalFilename: cluster.exe
PrivateBuild:
ProductName: cluster
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0810 0x04b0

Win32/Injector.BDES also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.c4e911dc9c6b1424
CAT-QuickHealTrojanPWS.Zbot.AP4
McAfeePWSZbot-FXE!C4E911DC9C6B
CylanceUnsafe
SangforTrojan.Win32.Lethic.4
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/DllCheck.80481335
K7GWTrojan ( 0040f8461 )
K7AntiVirusTrojan ( 0040f8461 )
VirITTrojan.Win32.SHeur4.BUYL
CyrenW32/Zbot.RS.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Injector.BDES
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-57618
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Lethic.Gen.4
NANO-AntivirusTrojan.Win32.Inject.cxiprh
SUPERAntiSpywareTrojan.Agent/Gen-Zeus
MicroWorld-eScanTrojan.Lethic.Gen.4
AvastWin32:Crypt-REG [Trj]
TencentMalware.Win32.Gencirc.10b4539e
Ad-AwareTrojan.Lethic.Gen.4
EmsisoftTrojan.Lethic.Gen.4 (B)
ComodoTrojWare.Win32.Injector.BDES@59xvmr
DrWebTrojan.PWS.Panda.5676
VIPRETrojan.Win32.Agent.bciw (v)
TrendMicroTROJ_FYNLOSK.SM1
McAfee-GW-EditionPWSZbot-FXE!C4E911DC9C6B
SophosMal/Generic-R + Troj/Fondu-AS
GDataTrojan.Lethic.Gen.4
JiangminTrojanSpy.Zbot.edwu
eGambitUnsafe.AI_Score_99%
AviraTR/Mantsu.vxca
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Lethic.Gen.4
ViRobotTrojan.Win32.S.Injector.512000
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/DllCheck.A!MSR
AhnLab-V3Trojan/Win32.Injector.R106674
BitDefenderThetaGen:NN.ZexaF.34212.Fq0@aWrXqClb
ALYacTrojan.Lethic.Gen.4
VBA32OScope.Malware-Cryptor.Zbot
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_FYNLOSK.SM1
RisingBackdoor.Fynloski!8.1FD (TFE:5:egSnxTjJLGL)
YandexTrojan.Agent!xLCgc/Y5y+k
IkarusVirus.Win32.Zbot
MaxSecureTrojan.Malware.7036746.susgen
FortinetW32/Krypt.DE!tr
WebrootW32.Rogue.Gen
AVGWin32:Crypt-REG [Trj]
Cybereasonmalicious.c9c6b1
PandaTrj/Genetic.gen

How to remove Win32/Injector.BDES?

Win32/Injector.BDES removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment