Malware

Win32/Injector.CGPS information

Malware Removal

The Win32/Injector.CGPS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CGPS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.CGPS?


File Info:

name: 74C8A3A20BEF2CDB2962.mlw
path: /opt/CAPEv2/storage/binaries/8d1f29f2759e584bac017a8332e7213b09982e6593c1baa0da0bb73a2a4b4fa6
crc32: 06AD5141
md5: 74c8a3a20bef2cdb29629d2cd79c55ca
sha1: dd9f3fd1d3ebd925ed7cd9ecc0df2728d1423817
sha256: 8d1f29f2759e584bac017a8332e7213b09982e6593c1baa0da0bb73a2a4b4fa6
sha512: a96846fc199a10284ec8c861c824bca25740d38d48d71f14b852a4fad6463ad85779d9c0a17413d904d1ace07129e0b0be52e9ae552cae83759eb52c619af445
ssdeep: 1536:OxMSqmBpSaGvMHFc8wyKmQzmpr9JjPQPTBTvbWclG:CMSqmBp+kwyJrPklLbi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BC3AD2EF52A8656E06DB271E072075CA72A9C651F9815FF13703D1CE9322E62E3325F
sha3_384: 16ac726843d62a7aa5b8454c8bf082e96dcbc5f4ebf88b7f192d382f98d55633c368d5d28369a468a5f96709808b2ef5
ep_bytes: 908bec6a9068186b400068c030400064
timestamp: 2015-07-20 15:18:35

Version Info:

0: [No Data]

Win32/Injector.CGPS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Zbot.IQA
FireEyeGeneric.mg.74c8a3a20bef2cdb
CAT-QuickHealTrojanPWS.Zbot.A4
SkyhighPWSZbot-FAKV!74C8A3A20BEF
ALYacTrojan.Zbot.IQA
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Bulta.84d7b00b
K7GWTrojan ( 0055e3991 )
K7AntiVirusTrojan ( 0055e3991 )
ArcabitTrojan.Zbot.IQA
BitDefenderThetaAI:Packer.C11A80F520
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.CGPS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Zbot.IQA
NANO-AntivirusTrojan.Win32.Tepfer.dvcoqs
AvastWin32:Teerac-H [Trj]
RisingTrojan.Bulta!8.35D (TFE:1:XCGsoLxlaeH)
TACHYONTrojan/W32.Agent.118970.B
EmsisoftTrojan.Zbot.IQA (B)
F-SecureTrojan.TR/Spy.Zbot.xbboqj
DrWebBackDoor.Siggen.59606
ZillyaTrojan.Tepfer.Win32.81975
TrendMicroTROJ_GEN.R002C0DBN24
Trapminemalicious.high.ml.score
SophosMal/Zbot-UE
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bhrqx
WebrootTrojan.Dropper.Gen
VaristW32/Trojan.FU.gen!Eldorado
AviraTR/Spy.Zbot.xbboqj
Antiy-AVLTrojan[PSW]/Win32.Tepfer
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Spy.Zbot.BNM@60owbz
MicrosoftTrojan:Win32/Bulta!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Zbot.IQA
GoogleDetected
McAfeePWSZbot-FAKV!74C8A3A20BEF
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DBN24
TencentMalware.Win32.Gencirc.11bbe8bf
YandexTrojan.GenAsa!/bYN9wYyjic
IkarusTrojan.Zbot
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Injector.CGOP!tr
AVGWin32:Teerac-H [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Zbot.IQA

How to remove Win32/Injector.CGPS?

Win32/Injector.CGPS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment