Malware

Win32/Injector.CFGK removal tips

Malware Removal

The Win32/Injector.CFGK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CFGK virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.CFGK?


File Info:

crc32: 0E079994
md5: dccaefb12a4848e6309aec68b5658835
name: DCCAEFB12A4848E6309AEC68B5658835.mlw
sha1: bb99ef2bfa815264326668b816aa9ac4374e9d56
sha256: 328a26678e4dd7d7950efc622336c4942e65e0f1c6b26d2dfe1ae55662baab52
sha512: 8a18b52ce0dbf9faed58005fa7b96284ec40c87b087784223bcbd6807d24a7e48c91ef7de392a15d5e016a5e29ee3b34099eea30c5fc4af082f935b811102066
ssdeep: 12288:rHaSED2XRzmO4SLKybkg4pO7xB8FDoB9IoN+UOhryOu3rZjLBtk9rt0G5DGj:rHGaiOLjwZpOFoE7eC3989xDGj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.CFGK also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055dd191 )
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.59488
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Bagsu.19783
ALYacTrojan.Ransomware.GenericKD.41386564
CylanceUnsafe
ZillyaTrojan.Onion.Win32.280
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Injector.34c36ea3
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.12a484
CyrenW32/Trojan.QZPZ-2314
SymantecRansom.Enciphered
ESET-NOD32a variant of Win32/Injector.CFGK
APEXMalicious
AvastWin32:Teerac-H [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransomware.GenericKD.41386564
NANO-AntivirusTrojan.Win32.Dofoil.dufoti
SUPERAntiSpywareRansom.CryptoLocker/Variant
MicroWorld-eScanTrojan.Ransomware.GenericKD.41386564
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.Ransomware.GenericKD.41386564
SophosML/PE-A + Troj/Ransom-AZM
ComodoMalware@#2tvp1kggl53la
BitDefenderThetaGen:NN.ZexaF.34678.UqW@aKPlXgse
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_CRYPCTB.B
McAfee-GW-EditionPWSZbot-FAKV!DCCAEFB12A48
FireEyeGeneric.mg.dccaefb12a4848e6
EmsisoftTrojan.Ransomware.GenericKD.41386564 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.bhnya
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1126007
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftTrojan:Win32/Dorv.A!rfn
ArcabitTrojan.Ransomware.Generic.D2778244
AegisLabTrojan.Win32.Onion.j!c
GDataTrojan.Ransomware.GenericKD.41386564
AhnLab-V3Trojan/Win32.Miuref.R157824
McAfeePWSZbot-FAKV!DCCAEFB12A48
MAXmalware (ai score=100)
VBA32Hoax.Onion
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_CRYPCTB.B
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.GenAsa!lXVtoDL6Cr0
IkarusTrojan.Win32.Injector
FortinetW32/Injector.CKLK!tr
AVGWin32:Teerac-H [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dorv.HwcBEpsA

How to remove Win32/Injector.CFGK?

Win32/Injector.CFGK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment