Malware

Win32/Injector.BDGK removal tips

Malware Removal

The Win32/Injector.BDGK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BDGK virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

iphanyi.duckdns.org

How to determine Win32/Injector.BDGK?


File Info:

crc32: C36743C9
md5: d0e7b058e35b998134e771b24f534b07
name: upload_file
sha1: 9711b4478564484da540866df48c117f9d96fd4f
sha256: 249e738650027df7635aa70373e2e2f936eb58e1a208fdc8df9ee2f66e4cb9e3
sha512: 7f1b2c67f375a6225754a65eba3bcaed355672553265d70e16c0da4fbbd81c27a07d728f4cfccb1458a7d75061aa8b0d562db8e0f58fb03b82fdd671534ad506
ssdeep: 12288:pMEuFTG5ys/bVmOQEXrsZVA+m2WwlJD3RDBs4mx98Ad1iMCDp:eEX5yUxrHrDqRYxd1E9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: SubZero DeZigns
InternalName: Checker
FileVersion: 2.00
CompanyName: SubZero DeZigns
LegalTrademarks: Mini Sub
Comments: This file is used for checking dll ocx files.
ProductName: DLL OCX Checker.
ProductVersion: 2.00
FileDescription: SubZero's Mini Sub DLL OCX Checker.
OriginalFilename: Checker.exe

Win32/Injector.BDGK also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34376929
FireEyeGeneric.mg.d0e7b058e35b9981
CAT-QuickHealTrojan.Multi
McAfeeGenericRXLS-GH!D0E7B058E35B
CylanceUnsafe
AegisLabTrojan.Win32.NetWire.4!c
K7AntiVirusTrojan ( 0049a6ee1 )
BitDefenderTrojan.GenericKD.34376929
K7GWTrojan ( 0049a6ee1 )
Cybereasonmalicious.785644
TrendMicroPUA.Win32.Wacatac.USXVPHI20
BitDefenderThetaGen:NN.ZevbaF.34196.Um3@aacHmjci
CyrenW32/Trojan.MCPB-6215
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallPUA.Win32.Wacatac.USXVPHI20
Paloaltogeneric.ml
KasperskyTrojan.Win32.NetWire.jpv
AlibabaTrojan:Win32/NetWire.458ed74d
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.34376929
ComodoTrojWare.Win32.Genome.xfcee@0
F-SecureTrojan.TR/Injector.lyrxe
VIPRETrojan.Win32.Generic!BT
SophosMal/Generic-S
APEXMalicious
AviraTR/Injector.lyrxe
MicrosoftTrojan:Win32/Ymacco.AA24
ArcabitTrojan.Generic.D20C8CE1
ViRobotTrojan.Win32.Z.Injector.763118
ZoneAlarmTrojan.Win32.NetWire.jpv
GDataTrojan.GenericKD.34376929
CynetMalicious (score: 85)
AhnLab-V3Unwanted/Win32.Agent.C4182666
VBA32Trojan.NetWire
ALYacBackdoor.RAT.Netwire
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.VB
IkarusTrojan.VB.Crypt
ESET-NOD32a variant of Win32/Injector.BDGK.gen
TencentWin32.Trojan.Netwire.Wrqd
SentinelOneDFI – Malicious PE
FortinetW32/Injector.DAJK!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.fda

How to remove Win32/Injector.BDGK?

Win32/Injector.BDGK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment