Malware

How to remove “Win32/Injector.BFSU”?

Malware Removal

The Win32/Injector.BFSU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BFSU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.BFSU?


File Info:

crc32: D4DA0849
md5: 8d468a832b36a758dcdf7ba9430c092c
name: 8D468A832B36A758DCDF7BA9430C092C.mlw
sha1: df438925c21adb7232b49ee1db456f55569d1004
sha256: b40de051760ceaf9fdfadcad0354475f7b1ecaf40f695932f5ba8942365c649b
sha512: d0a48fca70ba70ecdb7e5ad1d8a5e3279b5389eeab8b22ec37d692d7b84a300f57f19e11f000c8f178bed20d690c8bd9261d9f790b6358e2b0f0bdea6ae6767e
ssdeep: 768:673gDhPgQOlfi9gNxOideP18KboZ897T+Z:kgDqQjimqGoZ89WZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Win32/Injector.BFSU also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.448218
CAT-QuickHealTrojan.Dorv.18436
ALYacGen:Variant.Razy.448218
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 0040f54b1 )
BitDefenderGen:Variant.Razy.448218
K7GWTrojan-Downloader ( 0040f54b1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Inject.bm
CyrenW32/Rubin.A.gen!Eldorado
SymantecTrojan.Cryect
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.Rubinurd-67
KasperskyHEUR:Trojan.Win32.Miancha.gen
NANO-AntivirusTrojan.Win32.Small.cpelw
ViRobotBackdoor.Win32.Agent.36864.BO
RisingTrojan.Inejctor!1.A7C6 (CLASSIC)
Ad-AwareGen:Variant.Razy.448218
EmsisoftGen:Variant.Razy.448218 (B)
ComodoTrojWare.Win32.Injector.ccu@4zdswy
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop1.44208
TrendMicroTROJ_GEN.R03BC0CAV21
McAfee-GW-EditionBehavesLike.Win32.Downloader.nm
FireEyeGeneric.mg.8d468a832b36a758
SophosML/PE-A + Troj/DwnLdr-MDK
IkarusTrojan-Downloader.Win32.Small
JiangminTrojanDownloader.Small.akap
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Dorv.A!rfn
ArcabitTrojan.Razy.D6D6DA
ZoneAlarmHEUR:Trojan.Win32.Miancha.gen
GDataGen:Variant.Razy.448218
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R885
Acronissuspicious
McAfeeDownloader-BIJ.a
MAXmalware (ai score=84)
VBA32BScope.Trojan.Occamy
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.BFSU
TrendMicro-HouseCallTROJ_GEN.R03BC0CAV21
YandexTrojan.GenAsa!GIDBK2aXaUc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BFSU!tr
BitDefenderThetaAI:Packer.F0EB163B1F
AVGWin32:Evo-gen [Susp]
Qihoo-360HEUR/QVM19.1.0745.Malware.Gen

How to remove Win32/Injector.BFSU?

Win32/Injector.BFSU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment