Malware

What is “Win32/Injector.CANX”?

Malware Removal

The Win32/Injector.CANX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CANX virus can do?

  • Unconventionial binary language: Bulgarian
  • Unconventionial language used in binary resources: Bulgarian
  • Anomalous binary characteristics

How to determine Win32/Injector.CANX?


File Info:

crc32: 85E4CE83
md5: b87e150a4d9360edd4868f74404a5aa0
name: B87E150A4D9360EDD4868F74404A5AA0.mlw
sha1: 1e619db890464f1e28a8403d9b6e7c084a7225cd
sha256: 02c992378ac2181137f84bad69a2bbdbf5706d4b3d31e2b70c8e2373303f4617
sha512: 70eac7f876c00d30307279e5001fc7d8656c8edc7121829622824959d5423051f68a50ed21e12edd63d554e21fc12d83fef4bf940d034c6fe6b38c51b7ba2b41
ssdeep: 3072:tBufqWYGF0m7m+V4lEjuGRrkDVRe6x1AMlO3iQUmwGL:Y10uV4lEjhrkBkYl+JwG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0402 0x04b0
InternalName: Hayabusa
FileVersion: 4.05.0003
CompanyName: Hayabusa
ProductName: Regungen
ProductVersion: 4.05.0003
OriginalFilename: Hayabusa.exe

Win32/Injector.CANX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.Spambot.12689
ClamAVWin.Dropper.NetWire-9817697-0
CAT-QuickHealTrojanPWS.Zbot.VA3
ALYacGen:Heur.PonyStealer.km1@ei@k4FgG
ZillyaBackdoor.Tofsee.Win32.981
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Heur.PonyStealer.km1@ei@k4FgG
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.a4d936
ESET-NOD32a variant of Win32/Injector.CANX
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyBackdoor.Win32.Tofsee.yid
NANO-AntivirusTrojan.Win32.Tofsee.drrgyk
MicroWorld-eScanGen:Heur.PonyStealer.km1@ei@k4FgG
TencentWin32.Backdoor.Tofsee.Pgda
Ad-AwareGen:Heur.PonyStealer.km1@ei@k4FgG
ComodoMalware@#x9a44zmk8jms
BitDefenderThetaAI:Packer.D46A081321
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.b87e150a4d9360ed
EmsisoftGen:Heur.PonyStealer.km1@ei@k4FgG (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1119928
eGambitUnsafe.AI_Score_99%
MicrosoftPWS:Win32/Zbot!ml
SUPERAntiSpywareTrojan.Agent/Gen-VB
GDataGen:Heur.PonyStealer.km1@ei@k4FgG
VBA32Backdoor.Tofsee
MAXmalware (ai score=83)
YandexBackdoor.Tofsee!YrKT8Iky9/4
IkarusTrojan.Win32.Injector
FortinetW32/Injector.CGKI!tr
PandaTrj/Genetic.gen

How to remove Win32/Injector.CANX?

Win32/Injector.CANX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment