Malware

About “Win32/Injector.CKLL” infection

Malware Removal

The Win32/Injector.CKLL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CKLL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

food-fishltd.in.net

How to determine Win32/Injector.CKLL?


File Info:

crc32: 3D33351E
md5: db3c1c862c73856680d4694898c50f71
name: DB3C1C862C73856680D4694898C50F71.mlw
sha1: 911af0fe756d8776b68d8d8252e45d39f9b17162
sha256: f06cfaec657afad171e87f2baa49e39b61ebaac8869578e464fc6e2ae8a6fc69
sha512: 7fa5dcbee6b3cd30f72839c4e66637a6b52c1c4261897f97c805c26c72425843b22657f0f6c1b2b106f0e0f562f8a1dc7f3921925721434297f6e2616f8fa6d2
ssdeep: 1536:YUkUcDHHHHHHH6HHAhPx2Z7B+gya8rdaO8HJQObGNIghE6QZ:YCc7x2hbF8r/wQOKmU2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Leander
FileVersion: 1.01.0001
Comments: Blazonment
ProductName: Anfillo2
ProductVersion: 1.01.0001
FileDescription: Zerbst
OriginalFilename: Leander.exe

Win32/Injector.CKLL also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader17.14819
CynetMalicious (score: 99)
CAT-QuickHealTrojanPWS.Zbot.AC3
ALYacTrojan.GenericKD.2797417
CylanceUnsafe
ZillyaAdware.BrowseFox.Win32.134625
SangforBackdoor.Win32.Androm.8
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Androm.37bfbf42
Cybereasonmalicious.62c738
CyrenW32/VBKrypt.WT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CKLL
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Androm.iljn
BitDefenderTrojan.GenericKD.2797417
NANO-AntivirusTrojan.Win32.Dwn.dxwmal
MicroWorld-eScanTrojan.GenericKD.2797417
TencentWin32.Backdoor.Androm.Wrqi
Ad-AwareTrojan.GenericKD.2797417
SophosMal/Generic-R + Mal/FareitVB-X
ComodoMalware@#25xl9x9torasl
BitDefenderThetaGen:NN.ZevbaF.34266.hm0@aCKmh9ji
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_VBKRYPT.XFB
McAfee-GW-EditionTrojan-FHFA!DB3C1C862C73
FireEyeGeneric.mg.db3c1c862c738566
EmsisoftTrojan.GenericKD.2797417 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.aes
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1133459
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1526E06
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataTrojan.GenericKD.2797417
AhnLab-V3Trojan/Win32.Vbkrypt.C1114706
McAfeeTrojan-FHFA!DB3C1C862C73
MAXmalware (ai score=88)
VBA32Backdoor.Androm
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_VBKRYPT.XFB
YandexTrojan.Injector!eRmggpcXZaE
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.FCS!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.CKLL?

Win32/Injector.CKLL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment