Malware

What is “Win32/Injector.CSEM”?

Malware Removal

The Win32/Injector.CSEM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CSEM virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Injector.CSEM?


File Info:

crc32: 72EE1643
md5: 8490c76397a82ab04103766289e3597f
name: 8490C76397A82AB04103766289E3597F.mlw
sha1: 6023e28740521889695388251d48141ecd74adbb
sha256: 3f41a5bd2d7b5676a5c98f13d0245265c6faaf01b3893d0af0963c06718d6381
sha512: 4765ad95f2c4e403044ab0e5db3e3193403c756af76d1c8c452dfda81d90b840f535038b0d215e077d6200d7c3918d249fc521786f3ca6c7ee661adf630d4f8c
ssdeep: 12288:BGAG5gGhgOj0KFe4pAfTAkCOj0KFe4piwQwd:BGrSKs4peTUKs4piwLd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013
InternalName: Clearness
FileVersion: 172, 90, 135, 252
CompanyName: Massive Entertainment AB
PrivateBuild: 71, 129, 73, 136
LegalTrademarks: Emirates
Comments: Fistful
ProductName: Deter Competed
SpecialBuild: 109, 67, 198, 47
ProductVersion: 47, 63, 72, 29
FileDescription: Dismount Crumbs Citizenship
OriginalFilename: Crackersl.EXE

Win32/Injector.CSEM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.59903
CynetMalicious (score: 100)
CAT-QuickHealRansom.Teslacrypt.OL4
ALYacGen:Variant.Cripack.3
CylanceUnsafe
ZillyaTrojan.Injector.Win32.364021
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.397a82
BaiduWin32.Trojan.Filecoder.k
SymantecRansom.TeslaCrypt!g4
ESET-NOD32a variant of Win32/Injector.CSEM
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Cripack.3
NANO-AntivirusTrojan.Win32.AVKill.ealwff
MicroWorld-eScanGen:Variant.Cripack.3
TencentMalware.Win32.Gencirc.10c2ed59
Ad-AwareGen:Variant.Cripack.3
SophosML/PE-A + Mal/Ransom-EK
BitDefenderThetaGen:NN.ZexaF.34170.Iq0@am2fIkp
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.8490c76397a82ab0
EmsisoftGen:Variant.Cripack.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Tpyn.xi
Webroot
AviraHEUR/AGEN.1122415
Antiy-AVLTrojan/Generic.ASMalwS.171739B
KingsoftWin32.Troj.Tpyn.v.(kcloud)
MicrosoftRansom:Win32/Tescrypt.H
GDataGen:Variant.Cripack.3
AhnLab-V3Trojan/Win32.Teslacrypt.R173404
Acronissuspicious
McAfeeRansomware-FDS!8490C76397A8
MAXmalware (ai score=86)
VBA32Trojan.AVKill
MalwarebytesRansom.FileLocker
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPLOCKY.SM1
RisingTrojan.Agent!1.A322 (CLASSIC)
YandexTrojan.Injector!zAFty/2KP1c
IkarusTrojan.Win32.Crypt
FortinetW32/Injector.CSAW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.CSEM?

Win32/Injector.CSEM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment