Malware

Win32/Injector.CFGO removal

Malware Removal

The Win32/Injector.CFGO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CFGO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Injector.CFGO?


File Info:

name: C4F340740C9DA881F288.mlw
path: /opt/CAPEv2/storage/binaries/49451558b07afd95c82e4a8feda1d83cf35a4bf18c7eb144acbbf023646b4868
crc32: AB2D91CD
md5: c4f340740c9da881f288e6ec9c739f11
sha1: 3b7367fd05d7b5cab03c53d4b60016f667b12776
sha256: 49451558b07afd95c82e4a8feda1d83cf35a4bf18c7eb144acbbf023646b4868
sha512: 33f72623732238114d52828b59a59243289222de4cc6343c1e7113cf60de2082fac5f41a5a3d67af3e4b209df34d51071356fd68c388a6d271653e878565cbc4
ssdeep: 1536:8UHuEvVMxb9o0YiOaIO7m/6VqRGsli2TG0zP2zQD+GM:8UHuEvc60VORmmCVqGsxFPUQDvM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A63E1E59D200067C12082341A7BEAB275F9C876FF53D9CFB9028E4FA97279C251365E
sha3_384: 647bcc215d9ae16373d29e88a317b13c866a8dd9fa537df44edb9804955109f4a16b2052f84b84b61511a1f3c9fe5c2f
ep_bytes: 558bec6aff68d026400068a21d400064
timestamp: 2015-07-07 18:27:33

Version Info:

0: [No Data]

Win32/Injector.CFGO also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1376
MicroWorld-eScanTrojan.Downloader.JRZV
FireEyeGeneric.mg.c4f340740c9da881
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-FB!C4F340740C9D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004c7e1e1 )
AlibabaTrojan:Win32/Dorv.d35b828a
K7GWTrojan ( 004c7e1e1 )
Cybereasonmalicious.40c9da
BitDefenderThetaGen:NN.ZexaF.34212.eqZ@aGYKvVe
VirITTrojan.Win32.Inject2.CNOA
CyrenW32/S-1bc9580e!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.CFGO
TrendMicro-HouseCallBKDR_KELIHOS.SMNA
Paloaltogeneric.ml
ClamAVWin.Malware.Blkx-6951312-0
KasperskyTrojan.Win32.Agent.ifuw
BitDefenderTrojan.Downloader.JRZV
NANO-AntivirusTrojan.Win32.Encoder.dufbcp
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastSf:Agent-BA [Trj]
TencentMalware.Win32.Gencirc.10b0f85b
Ad-AwareTrojan.Downloader.JRZV
TACHYONTrojan/W32.Agent.70330.G
SophosMal/Generic-R + Mal/Zbot-UE
ComodoMalware@#3b2snbxjwe3j
ZillyaTrojan.Injector.Win32.376081
TrendMicroBKDR_KELIHOS.SMNA
McAfee-GW-EditionPacked-FB!C4F340740C9D
EmsisoftTrojan.Downloader.JRZV (B)
GDataTrojan.Downloader.JRZV
JiangminTrojan/Agent.ijuv
WebrootW32.Trojan.Gen
AviraTR/Inject.sbbeinx
Antiy-AVLTrojan/Generic.ASBOL.2545
KingsoftWin32.Troj.Agent.if.(kcloud)
ArcabitTrojan.Downloader.JRZV
ZoneAlarmTrojan.Win32.Agent.ifuw
MicrosoftTrojan:Win32/DllCheck.A!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CTBLocker.R158760
Acronissuspicious
VBA32OScope.Malware-Cryptor.Hlux
ALYacTrojan.Downloader.JRZV
MAXmalware (ai score=100)
MalwarebytesMalware.AI.798183777
APEXMalicious
RisingTrojan.Senta!8.66F (CLOUD)
YandexTrojan.Agent!ZXe2GfQxC3k
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.CFFW!tr
AVGSf:Agent-BA [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.CFGO?

Win32/Injector.CFGO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment