Malware

Win32/Injector.BGXC removal tips

Malware Removal

The Win32/Injector.BGXC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BGXC virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Injector.BGXC?


File Info:

name: E6B34E975BA344BB900F.mlw
path: /opt/CAPEv2/storage/binaries/b5ae27db435d08b964a3c8111e12f0cface50ee7b16fde7c91bd54b12b378838
crc32: 0BB83490
md5: e6b34e975ba344bb900f11ad0ddaadb1
sha1: c1e4c284057a92bc4b47e97934c8cce6033c20e2
sha256: b5ae27db435d08b964a3c8111e12f0cface50ee7b16fde7c91bd54b12b378838
sha512: cf097c6596070ecfa9e6baf5798354a17c4a83fac03a130b296c12e66653a47bcc1353911da57dba8e14556eb8887a0df999a2ce265f2300b29533f637173580
ssdeep: 1536:5e2pciNi+yTscB/+7xawIc7X5BJzvZjiaDqf9+PilsYKpW:vLWscB/aAwVJnzNiaG1fU0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F615F55197407958C8BB03B48DEEAAE67B351D24C726D8A6F34229DF87D127183D1F83
sha3_384: ff49d68b30e846bf945cf21934fa968f9c03eef5cf54839c092e503cb4486b66930731c11d3afa827507f1926706544e
ep_bytes: 68789d4400e8f0ffffff000050000000
timestamp: 2014-06-15 16:17:49

Version Info:

Translation: 0x0409 0x04b0
Comments: Þ2QIBwì±8Enòa蜜sÁmz
CompanyName: žKj7rt£žnœBìH™svÚõjœ
FileDescription: ™kyVdžHzƒzyoœò1ÞDQDz
LegalCopyright: £võœœæO±žÚzs1œ3BBOœB
LegalTrademarks: zœ«zOõ3qsœwõZžœÞõMžh
ProductName: 4xkœÚ±uœ0sòÚFHkœBèHÞ
FileVersion: 7.01.0022
ProductVersion: 7.01.0022
InternalName: limpo
OriginalFilename: limpo.exe

Win32/Injector.BGXC also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.KillFiles.16371
MicroWorld-eScanGen:Variant.Barys.319924
FireEyeGeneric.mg.e6b34e975ba344bb
CAT-QuickHealTrojan.VBCrypt.MF.82
ALYacGen:Variant.Barys.319924
CylanceUnsafe
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0049d96f1 )
K7AntiVirusTrojan ( 0049d96f1 )
ArcabitTrojan.Barys.D4E1B4
BitDefenderThetaGen:NN.ZevbaF.34698.6m3@aWkt8Qpi
VirITTrojan.Win32.Inject2.AVPP
CyrenW32/VBKrypt.ALQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.BGXC
APEXMalicious
ClamAVWin.Dropper.DarkKomet-9204913-0
KasperskyTrojan.Win32.Agent.nesavs
BitDefenderGen:Variant.Barys.319924
NANO-AntivirusTrojan.Win32.KillFiles.fmiltx
AvastWin32:TrojanX-gen [Trj]
RisingWorm.Rebhip!8.B31 (TFE:3:0hsExmn7lzQ)
Ad-AwareGen:Variant.Barys.319924
EmsisoftGen:Variant.Barys.319924 (B)
ComodoTrojWare.Win32.VB.DRPF@5hzrzj
VIPREGen:Variant.Barys.319924
TrendMicroTROJ_GEN.R014C0PJ622
McAfee-GW-EditionGenericRXAE-LP!E6B34E975BA3
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Agent.hzsy
GoogleDetected
AviraTR/Symmi.olaks
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.51F4
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Barys.319924
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Symmi.R139961
Acronissuspicious
McAfeeGenericRXAE-LP!E6B34E975BA3
TACHYONTrojan/W32.VB-Agent.954422
VBA32Trojan.Agent
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R014C0PJ622
TencentTrojan.Win32.Agent.hx
YandexTrojan.GenAsa!03KA44XY5WM
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BLMO!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.75ba34
PandaTrj/GdSda.A

How to remove Win32/Injector.BGXC?

Win32/Injector.BGXC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment