Malware

Win32/Injector.CFPU information

Malware Removal

The Win32/Injector.CFPU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CFPU virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Attempts to ensure mapped drives are available from an elevated prompt or process with UAC enabled
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Injector.CFPU?


File Info:

name: 611A6AED1E0512E6D05D.mlw
path: /opt/CAPEv2/storage/binaries/1cdacebd8738bb4f54243e8b29ffff66f775a5dede8a0b2faa57a04913965bde
crc32: 2B768B90
md5: 611a6aed1e0512e6d05d9d9467737cc0
sha1: 8494b9ad7cf8ae5b36b99e8b8ae09d5efecf8956
sha256: 1cdacebd8738bb4f54243e8b29ffff66f775a5dede8a0b2faa57a04913965bde
sha512: b88386464a81bcf9ba4ee2565a4a0eb417e4f2fda881590320562a0e302c7d0675e367e56cf99e52c60e0d26984a6921f0b887f3cb5f9eb274363ed526b667c7
ssdeep: 6144:mjRDz/yATDbXlp5SgCYxxf80yaiAfgyESXahHaegInF05:mtDz6gDb1hCWfuATXah6a0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140A4BFFB6444A8A6C517BEB46C17EEE3070678B586609BC76640D28E0E637F32D3705B
sha3_384: aad41d7c0dfc6d27bf718361da3c025fb3abb401cb4990f919e367d97452a7d21e15af2d8a942f0d141ed8bd96d73752
ep_bytes: e8a5140000e97ffeffff558becff35a8
timestamp: 2015-07-25 16:08:50

Version Info:

0: [No Data]

Win32/Injector.CFPU also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Bitman.j!c
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.37459
FireEyeGeneric.mg.611a6aed1e0512e6
CylanceUnsafe
ZillyaTrojan.Bitman.Win32.311
SangforTrojan.Win32.Save.a
K7AntiVirusRansomware ( 00564f7e1 )
AlibabaRansom:Win32/Bitman.3402b513
K7GWRansomware ( 00564f7e1 )
BitDefenderThetaGen:NN.ZexaF.34698.EqW@aebe5goi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CFPU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Bitman.us
NANO-AntivirusTrojan.Win32.Bitman.duqovm
AvastWin32:TeslaCrypt-M [Trj]
TencentMalware.Win32.Gencirc.10c87aed
ComodoMalware@#3drhfqk94voih
TrendMicroRansom_Tescrypt.R067C0DJ422
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Bitman.hd
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraHEUR/AGEN.1228660
Antiy-AVLTrojan/Generic.ASMalwS.411C
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tescrypt.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tescrypt.R160486
McAfeeGenericR-ECO!611A6AED1E05
MAXmalware (ai score=100)
VBA32Hoax.Bitman
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallRansom_Tescrypt.R067C0DJ422
RisingTrojan.Generic@AI.94 (RDML:VjRWgJXzp2GJv83wEsXecA)
YandexTrojan.Bitman!1MiPjVUuwbs
IkarusTrojan.Win32.Injector
FortinetW32/Injector.CFMW!tr
AVGWin32:TeslaCrypt-M [Trj]
Cybereasonmalicious.d1e051
PandaGeneric Suspicious

How to remove Win32/Injector.CFPU?

Win32/Injector.CFPU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment