Malware

About “Win32/Injector.BOBS” infection

Malware Removal

The Win32/Injector.BOBS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.BOBS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Win32/Injector.BOBS?


File Info:

name: B7A96743ADD71D005966.mlw
path: /opt/CAPEv2/storage/binaries/f16a8e6dd44159af74a7e7c179a06f233dedb111ca7cde6cefe30dcb3e606f02
crc32: 1C9F54AB
md5: b7a96743add71d005966b1b58e46186f
sha1: 45c7644bb24b3cf94f53fc115c71ec896e51689b
sha256: f16a8e6dd44159af74a7e7c179a06f233dedb111ca7cde6cefe30dcb3e606f02
sha512: f6e55c17994021d07b5180ca9caf97664b7e91e9287601f6c1b31d89f59d95b630a3855c1c958c445c4c123a974b5667e406cf5e61b052a59d903d2019265c58
ssdeep: 49152:+BnQqyHxKMmxko6kDVEAVNsbUHVQD/98G51cCJyTEgBVltZ0:+BnQqyHxKMmDD1Vub0c/98ocCJyIgnlg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BA506AE73C66E3CF942C17C501C9919918CED7062B9D48DDF836BDBB8D4902A339987
sha3_384: 0ba56ad8f1380518e4ffdbc6f06591d7fc4252522bb4a4d3c066a1a2dda8f6e91e2299d029c421b386da5f69ad29fb2c
ep_bytes: 68c0174000e8f0ffffff0000ffcc3100
timestamp: 2021-11-30 23:34:31

Version Info:

0: [No Data]

Win32/Injector.BOBS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.DarkKomet.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.PT.goZ@bSc2A9
FireEyeGeneric.mg.b7a96743add71d00
McAfeeArtemis!B7A96743ADD7
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderGen:Trojan.Heur.PT.goZ@bSc2A9
K7GWTrojan ( 0058b4f01 )
Cybereasonmalicious.3add71
ArcabitTrojan.Heur.PT.E9A3D4
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BOBS
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.DarkKomet.iivx
Ad-AwareGen:Trojan.Heur.PT.goZ@bSc2A9
SophosMal/Generic-S
DrWebTrojan.VbCrypt.250
ZillyaTrojan.Injector.Win32.1289202
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftGen:Trojan.Heur.PT.goZ@bSc2A9 (B)
IkarusTrojan.Win32.Injector
AviraTR/Dropper.Gen
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Trojan.Heur.PT.goZ@bSc2A9
BitDefenderThetaAI:Packer.E4650AE11D
ALYacGen:Trojan.Heur.PT.goZ@bSc2A9
MAXmalware (ai score=87)
TrendMicro-HouseCallTROJ_GEN.R002C0WLA21
TencentMalware.Win32.Gencirc.11db08ba
YandexTrojan.GenAsa!5e4ffNDbeR0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/BOBS!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.BOBS?

Win32/Injector.BOBS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment