Malware

What is “Win32/Injector.CEUF”?

Malware Removal

The Win32/Injector.CEUF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CEUF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.CEUF?


File Info:

crc32: E8FBEFB5
md5: d25f1acc58a9d9185a7a4acb956e216e
name: D25F1ACC58A9D9185A7A4ACB956E216E.mlw
sha1: f4dee61828a4993dcccae77c76d3695d3b489702
sha256: a4dd9f1acc3396fa3190d2db9c110d0d2a1418baf110183a05225dfb1a008f3d
sha512: 531553aff3d30822a36545e22cca3090f08ac1175ee0434efc355727c402bef033fc19738f2f15510d1c51776f7d2c0cc246598476d53aefa2b305f2c36b7877
ssdeep: 6144:4dtgWvyDm5pn1prrYM7YsWDFCuW1e8k3Q59xo3EQn:wtg8pn1pgQ9ugeH3F3Dn
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.CEUF also known as:

K7AntiVirusTrojan ( 00506bdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.Cerber.2
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00506bdf1 )
Cybereasonmalicious.c58a9d
CyrenW32/S-3650669b!Eldorado
SymantecInfostealer.Limitail
ESET-NOD32a variant of Win32/Injector.CEUF
APEXMalicious
AvastWin32:RansomShade-B [Trj]
ClamAVWin.Trojan.AppWizard-9763600-1
KasperskyTrojan-Ransom.Win32.Shade.ug
BitDefenderGen:Heur.Ransom.Cerber.2
NANO-AntivirusTrojan.Win32.Encoder.duagzv
SUPERAntiSpywareTrojan.Agent/Gen-Kovter
MicroWorld-eScanGen:Heur.Ransom.Cerber.2
TencentMalware.Win32.Gencirc.10b3eab8
Ad-AwareGen:Heur.Ransom.Cerber.2
SophosML/PE-A + Mal/Zbot-UE
ComodoTrojWare.Win32.Bagsu.AF@5szj4v
BitDefenderThetaGen:NN.ZexaF.34692.xyX@airBlSeK
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
FireEyeGeneric.mg.d25f1acc58a9d918
EmsisoftGen:Heur.Ransom.Cerber.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Shade.c
AviraHEUR/AGEN.1120601
Antiy-AVLTrojan/Generic.ASMalwS.127E118
MicrosoftTrojan:Win32/DllCheck.A!MSR
AegisLabTrojan.Win32.Shade.tqva
ZoneAlarmTrojan-Ransom.Win32.Shade.ug
GDataWin32.Trojan-Ransom.Troldesh.B
AhnLab-V3Trojan/Win32.Miuref.R159490
Acronissuspicious
McAfeePWSZbot-FAKV!D25F1ACC58A9
MAXmalware (ai score=100)
VBA32Backdoor.Androm
MalwarebytesTrojan.Kovter.ED
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.98 (RDML:owhaYS0Cg9CPCkugDiyyeg)
YandexTrojanSpy.Zbot!8sgdRnjcLOU
FortinetW32/Generic.AC.1F4264!tr
AVGWin32:RansomShade-B [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.CEUF?

Win32/Injector.CEUF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment