Malware

Win32/Injector.CGOX removal guide

Malware Removal

The Win32/Injector.CGOX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CGOX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.CGOX?


File Info:

name: CE2CA0721BA4FF120594.mlw
path: /opt/CAPEv2/storage/binaries/2f5cdf82000640348282fc798de459f1959092b30d613ae1f5e9dc94af7649ae
crc32: C17B3BDE
md5: ce2ca0721ba4ff1205943646acb2a78a
sha1: 7282e378f3debc6f5fa9d56032e1e937198ea4a7
sha256: 2f5cdf82000640348282fc798de459f1959092b30d613ae1f5e9dc94af7649ae
sha512: aef0888eb4d6cf0aee30744477c5270ac725391d665ed64299bb88b3a81ca63615ad984dd45a0542942a31b95ddce39ca11c601c622ae6fe2f4098b49ed91a04
ssdeep: 1536:o8XSqmBpSaGvMHQOA/O3KhjM4d4hSXBxnMaAtvk8Ede:RXSqmBp+eA/5GY4IxFM/tPP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ACC39D2EB12A9656E51EB274E0B61B9C661AAC181F8D05FF13707E6DE4302F21D3324F
sha3_384: 59c491783d137c6479931dfbeb7b3f16758ddc57427bdca69d997bb8d2edd427ddc5744eeba5f5437f4ec4bb83943447
ep_bytes: 908bec6a9068186b400068c030400064
timestamp: 2015-07-20 15:18:35

Version Info:

0: [No Data]

Win32/Injector.CGOX also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Zbot.IQA
CAT-QuickHealTrojanPWS.Zbot.A4
SkyhighPWSZbot-FAKV!CE2CA0721BA4
McAfeePWSZbot-FAKV!CE2CA0721BA4
Cylanceunsafe
ZillyaDropper.Injector.Win32.69883
SangforTrojan.Win32.Zbot.Vatj
AlibabaTrojan:Win32/Bulta.fa0c8d94
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Zbot.IQA
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.CGOX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Zbot-9954294-0
KasperskyTrojan.Win32.Agent.igcq
BitDefenderTrojan.Zbot.IQA
NANO-AntivirusTrojan.Win32.Mods.duzzqr
AvastWin32:Teerac-H [Trj]
TencentMalware.Win32.Gencirc.10b655ac
TACHYONTrojan/W32.Agent.118970.B
EmsisoftTrojan.Zbot.IQA (B)
F-SecureTrojan.TR/Spy.Zbot.xbboqj
DrWebTrojan.Mods.163
VIPRETrojan.Zbot.IQA
TrendMicroTROJ_GEN.R002C0DCH24
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ce2ca0721ba4ff12
SophosMal/Zbot-UE
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bhrqx
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Spy.Zbot.xbboqj
VaristW32/Trojan.FU.gen!Eldorado
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Spy.Zbot.BNM@60owbz
MicrosoftTrojan:Win32/Bulta!rfn
ZoneAlarmTrojan.Win32.Agent.igcq
GDataTrojan.Zbot.IQA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R161622
BitDefenderThetaAI:Packer.85298BDE20
ALYacTrojan.Zbot.IQA
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DCH24
RisingTrojan.Injector!8.C4 (TFE:1:PnljTf3dFiR)
YandexTrojan.GenAsa!iDB/Ka03nYY
IkarusTrojan.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CGOP!tr
AVGWin32:Teerac-H [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Zbot.IQA

How to remove Win32/Injector.CGOX?

Win32/Injector.CGOX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment