Malware

Win32/Injector.CHBF (file analysis)

Malware Removal

The Win32/Injector.CHBF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CHBF virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.CHBF?


File Info:

crc32: 4A6A9467
md5: 4461e91a054834ee4ef50a50c0f498e0
name: 4461E91A054834EE4EF50A50C0F498E0.mlw
sha1: 87d854c2e41b4a445364d1631b9d1a0b112f43a9
sha256: 5f8350de66e526546a1e0de85d60f7f584694d996ccb5b400d1207cdf30b0cfb
sha512: 56466f1c7c9f3c7c7d510756dd29af9d212f7640bf2afdd2caf21f97646569d6a946c0877deb715d08ac292ca29a3b37f82c861a889532c9d383e3221ff2a664
ssdeep: 768:VB0lDIEwkcGPrsEAcfBxDFZtkf9nI6t+RDUtzDY8yEL0lD:VBoES4EBfpvUnI9wNLo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
LegalCopyright: Oracle Copyright xa9 2012
InternalName: 4
FileVersion: 0.00.0008
LegalTrademarks: Oracle
ProductName: Oracle
ProductVersion: 0.00.0008
FileDescription: Oracle
OriginalFilename: 4.dll

Win32/Injector.CHBF also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056faf61 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Generic-7587573-0
ALYacGen:Variant.Graftor.213466
K7GWTrojan ( 0056faf61 )
Cybereasonmalicious.a05483
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CHBF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
BitDefenderGen:Variant.Graftor.213466
NANO-AntivirusTrojan.Win32.Graftor.feybsq
MicroWorld-eScanGen:Variant.Graftor.213466
TencentWin32.Trojan.Graftor.Pboz
Ad-AwareGen:Variant.Graftor.213466
SophosMal/Generic-S
ComodoMalware@#2w6ah14jh3rtq
BitDefenderThetaGen:NN.ZevbaF.34294.Em0@aqfMe9aG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.gz
FireEyeGen:Variant.Graftor.213466
EmsisoftGen:Variant.Graftor.213466 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1116391
Antiy-AVLTrojan/Generic.ASMalwS.261782D
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Graftor.D341DA
GDataGen:Variant.Graftor.213466
AhnLab-V3Trojan/Win32.Agent.R217631
McAfeeArtemis!4461E91A0548
MAXmalware (ai score=96)
PandaTrj/GdSda.A
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!WUY7hNTuC7o
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CHBF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.CHBF?

Win32/Injector.CHBF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment