Malware

Win32/Injector.CFU removal guide

Malware Removal

The Win32/Injector.CFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CFU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.CFU?


File Info:

name: 029F49523C6200577B18.mlw
path: /opt/CAPEv2/storage/binaries/87c7def5907e1f262d1dbca3da6bc9070d6ea4cf257687bea14d4a0471640e80
crc32: AA5DD4BD
md5: 029f49523c6200577b18b8828c80eaf3
sha1: dc7fe4c721e3fa3e1fb8892e3b698b69dfa85953
sha256: 87c7def5907e1f262d1dbca3da6bc9070d6ea4cf257687bea14d4a0471640e80
sha512: dda9a35a97530cae47a7338b7c281fcd7244d7793ca93c5c461a98c79380ef53ea7e36129c39cdf171aae8554bd67454e3b73ca36181ab3861fc025629c2b16b
ssdeep: 3072:uvwNdjjQEn/pr768If+egmBKCAxq1/6qaM2SjDvWXb5rtyxnGSwBYPuf+zpQIA:1Ndjjnn/pIf+eg+KCHRRaMvjDuXbtoEr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F14019336D2D5A1E88E8E38F85628F4DA247C2EF964401F1B353DAA3174AB49138D76
sha3_384: 3d90bcf4c4b17e5eb742b275af353fbc5b030c3c335577184b9b2dc97635fab8c47ac3b4b0e5415ca562866b72b12a15
ep_bytes: 60be00a04b008dbe0070f4ff5783cdff
timestamp: 2011-08-23 14:26:14

Version Info:

Translation: 0x0409 0x04b0
Comments: NtBCAFrkrViixBE
CompanyName: majnoun
FileDescription: nTmYcBpnhzwSpNT
LegalCopyright: riwGppcOpL
ProductName: QsFsfGcbDlCos
FileVersion: 22.333.4444
ProductVersion: 22.333.4444
InternalName: Stub
OriginalFilename: Stub.exe

Win32/Injector.CFU also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lsDf
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Heur.ManBat.1
FireEyeGeneric.mg.029f49523c620057
CAT-QuickHealTrojan.VBCrypt.MF.774
SkyhighBehavesLike.Win32.Autorun.cc
McAfeeArtemis!029F49523C62
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.VBKrypt.Win32.114665
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
AlibabaVirTool:Win32/VBInject.28ea11d9
K7GWTrojan ( 0055e3991 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.A7D236C71F
VirITTrojan.Win32.X-Mallum.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CFU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-48879
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.Bifrost.ecktna
SUPERAntiSpywareTrojan.Agent/Gen-Faldesc[Cont]
AvastWin32:Bifrose-FAH [Trj]
TencentWin32.Trojan.Generic.Lajl
EmsisoftGen:Heur.ManBat.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Bifrost.24736
VIPREGen:Heur.ManBat.1
TrendMicroTROJ_GEN.R002C0DAO24
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-C
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.zwby
VaristW32/VBcrypt.B.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.HeurC.KVM006.a
MicrosoftTrojan:Win32/Occamy.C87
XcitiumTrojWare.Win32.VB.GE@4pqh5b
ArcabitTrojan.ManBat.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.ManBat.1
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R42849
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0DAO24
RisingTrojan.VBInject!1.6541 (CLOUD)
YandexTrojan.VBKrypt!4TwmlTdczcE
IkarusGen.Heur
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Refroso.BLC!tr
AVGWin32:Bifrose-FAH [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/ManBat

How to remove Win32/Injector.CFU?

Win32/Injector.CFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment