Malware

Win32/Injector.BIRZ malicious file

Malware Removal

The Win32/Injector.BIRZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BIRZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Injector.BIRZ?


File Info:

name: 9F68B5B1FEEFBEFEB2E3.mlw
path: /opt/CAPEv2/storage/binaries/c8d4191dcb0d5291c1c53b1538ad639e0ed6270925ef8db48536707a5ebe3bae
crc32: 5C786CBE
md5: 9f68b5b1feefbefeb2e344f5aad8f0e4
sha1: eafd11b8cc379446e9eeefb3543920e2bcc74fe4
sha256: c8d4191dcb0d5291c1c53b1538ad639e0ed6270925ef8db48536707a5ebe3bae
sha512: f5af820e99896381eeea2a584bcf631646436f45095018ffde81c1800ec90b933335795640e0086c7b30239ea0b51002a9c96d3b687a75c44d126cf3afd35c2e
ssdeep: 768:tR+F/SMzoh4IeafNq07Iip7t7e+PHItgC7SX7KCkDBNg8LMjfoCqOXThTQ:v+FGmIeafNq002BPyR7SX2EPjfP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2834A5B9D5700D6E208CC3086E622F19BFD9D573BD2AA7FDB18CC5D04B2458A8611BF
sha3_384: 1ebfdd28839116e7dfb1e3923aeadf26f1ba5ef2ed86e921af5d528429a1b2f5ce0e8cfb4fa83c5b91220a11df175450
ep_bytes: 558bec6aff68585a4000685645400064
timestamp: 2014-07-23 17:40:10

Version Info:

0: [No Data]

Win32/Injector.BIRZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.25573
FireEyeGeneric.mg.9f68b5b1feefbefe
CAT-QuickHealTrojan.CeeInject.WR
ALYacTrojan.GenericKDZ.25573
CylanceUnsafe
VIPRETrojan.Win32.Injector.birw (v)
SangforTrojan.Win32.GenericKDZ.frVs
K7AntiVirusTrojan ( 0058afbb1 )
AlibabaVirTool:Win32/CeeInject.dde9e22c
K7GWTrojan ( 0058afbb1 )
Cybereasonmalicious.1feefb
BaiduWin32.Trojan.Inject.bj
CyrenW32/Obuvka.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BIRZ
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.25573
NANO-AntivirusTrojan.Win32.DownLoad3.dcytlf
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Crypt-RFF [Trj]
TencentMalware.Win32.Gencirc.10bd955f
Ad-AwareTrojan.GenericKDZ.25573
SophosMal/Generic-R + Mal/Zbot-QU
ComodoTrojWare.Win32.Injector.BIWG@5dy0hg
DrWebTrojan.PWS.Panda.5841
ZillyaTrojan.Inject.Win32.86385
TrendMicroTSPY_ZBOT.SMYA
McAfee-GW-EditionGeneric-FAUV!9F68B5B1FEEF
EmsisoftTrojan.GenericKDZ.25573 (B)
IkarusTrojan.Win32.Cidox
JiangminTrojan-Downloader.Win32.Obuvka.f
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.B35A56
KingsoftWin32.Troj.Inject.oh.(kcloud)
MicrosoftVirTool:Win32/CeeInject
GDataTrojan.GenericKDZ.25573
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R114018
Acronissuspicious
McAfeeGeneric-FAUV!9F68B5B1FEEF
MAXmalware (ai score=88)
VBA32OScope.Malware-Cryptor.Hlux
MalwarebytesTrojan.Agent.ED
TrendMicro-HouseCallTSPY_ZBOT.SMYA
YandexBackdoor.Hlux!5T0btlnRzlc
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.BHSP!tr
BitDefenderThetaGen:NN.ZexaF.34294.fyW@aGQHmmcj
AVGWin32:Crypt-RFF [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.BIRZ?

Win32/Injector.BIRZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment