Malware

About “Win32/Injector.CJOL” infection

Malware Removal

The Win32/Injector.CJOL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CJOL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
semiproviprodu.com
teopredloparemit.com
presitoholeo.com

How to determine Win32/Injector.CJOL?


File Info:

crc32: 8C920CD9
md5: 0b792bed7dcf7fcbf2a37916da044610
name: upload_file
sha1: ec800fe0106148a81dd67f6cded226bf42749b39
sha256: 89b7c3305c4a45b9ef25eb9688b68744804c0beda4e884393e0f47d1b3f302eb
sha512: 98c53771749301626474ffa556755e1cc1d3ac5342b8586e084d9115e727a0d842256f47ec777f59a8550bceb72a7b2d16b2ee2182a22bfcd1e534b43fb1acbc
ssdeep: 3072:tCRyhifpOkVS5qWJc2P1msvovnPm+SYDe3pNozd0:t6yhEix4QpNozd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Cimenoza
FileVersion: 0.03.0008
CompanyName: Cimenoza
Comments: Cimenoza
ProductName: Arbeitsbibliographie
ProductVersion: 0.03.0008
FileDescription: Cimenoza
OriginalFilename: Cimenoza.exe

Win32/Injector.CJOL also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Heur.PonyStealer.km0@dOV6PLoi
FireEyeGeneric.mg.0b792bed7dcf7fcb
Qihoo-360HEUR/QVM03.0.Malware.Gen
McAfeePacked-FT!0B792BED7DCF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderGen:Heur.PonyStealer.km0@dOV6PLoi
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.d7dcf7
Invinceaheuristic
BitDefenderThetaGen:NN.ZevbaF.34090.km0@aOV6PLoi
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
GDataGen:Heur.PonyStealer.km0@dOV6PLoi
KasperskyTrojan.Win32.Scar.loxl
AlibabaWorm:Win32/Gamarue.9825a6e0
NANO-AntivirusTrojan.Win32.Scar.dxzfpv
AegisLabTrojan.Win32.Scar.4!c
APEXMalicious
TencentWin32.Trojan.Scar.Gvp
Ad-AwareGen:Heur.PonyStealer.km0@dOV6PLoi
SophosTroj/VBInj-MJ
ComodoMalware@#k6m891sbdey1
F-SecureHeuristic.HEUR/AGEN.1023841
ZillyaTrojan.Injector.Win32.331599
McAfee-GW-EditionPacked-FT!0B792BED7DCF
Trapminesuspicious.low.ml.score
EmsisoftGen:Heur.PonyStealer.km0@dOV6PLoi (B)
SentinelOneDFI – Malicious PE
JiangminTrojan.Scar.ns
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1023841
Antiy-AVLTrojan/Win32.Scar
Endgamemalicious (high confidence)
ArcabitTrojan.PonyStealer.EA482F
ZoneAlarmTrojan.Win32.Scar.loxl
MicrosoftWorm:Win32/Gamarue
AhnLab-V3Win-Trojan/VBKrand.Gen
Acronissuspicious
ALYacGen:Heur.PonyStealer.km0@dOV6PLoi
MAXmalware (ai score=86)
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.CJOL
RisingTrojan.Win32.Generic.19172427 (C64:YzY0OpHgQJgGKtKW)
YandexTrojan.Injector!jX2lN7bYmEo
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_95%
FortinetW32/GenKryptik.KTZ!tr
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.8837752.susgen

How to remove Win32/Injector.CJOL?

Win32/Injector.CJOL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment