Malware

About “Win32/Injector.CXHD” infection

Malware Removal

The Win32/Injector.CXHD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CXHD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.CXHD?


File Info:

crc32: A7358ACD
md5: 2e8c0b0971aff8d7e98aff55788b98b0
name: 2E8C0B0971AFF8D7E98AFF55788B98B0.mlw
sha1: 33c219338430c334c905fb77f6a69984c26dc4e2
sha256: aa775f3a985b66e1bbe60ef665dd3f332462289b3aed873e7ad244d9fe007560
sha512: deeaa1e2d376bd9984953d7b57a2784464c980b2dfcf7da810a3376133546372f7a982bb0806046d43600f308835081d941bc2efa1da034530909aba4705fa02
ssdeep: 12288:NSxDIWLr0tWDUOTT1qLJCt4nEJYq4lZCyKyErW5tVhgo9hcOdWJHJg+LPw7UAlC:NSxDIg1t40YtlZC3lW5yo9m5JgxC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: Cardif
InternalName: Jumanjj
FileVersion: 1.04.0004
CompanyName: _Connectify
LegalTrademarks: Cardif
Comments: Noon8
ProductName: Cardif
ProductVersion: 1.04.0004
FileDescription: Cardif
OriginalFilename: Jumanjj.exe

Win32/Injector.CXHD also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4989
CynetMalicious (score: 99)
ALYacGen:Heur.PonyStealer.4m0@eywcMhpb
CylanceUnsafe
ZillyaTrojan.Onion.Win32.1584
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Onion.be0236f8
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.971aff
SymantecInfostealer.Limitail
ESET-NOD32a variant of Win32/Injector.CXHD
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Onion.wbh
BitDefenderGen:Heur.PonyStealer.4m0@eywcMhpb
NANO-AntivirusTrojan.Win32.Encoder.egoubi
ViRobotTrojan.Win32.Z.Onion.929792
MicroWorld-eScanGen:Heur.PonyStealer.4m0@eywcMhpb
Ad-AwareGen:Heur.PonyStealer.4m0@eywcMhpb
SophosMal/Generic-R + Troj/CtbLock-L
ComodoMalware@#28dgwy9okhf4l
BitDefenderThetaGen:NN.ZevbaF.34738.4m0@aywcMhpb
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_CTBLOCKER.C
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.2e8c0b0971aff8d7
EmsisoftGen:Heur.PonyStealer.4m0@eywcMhpb (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Onion.ee
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1119911
eGambitUnsafe.AI_Score_84%
Antiy-AVLTrojan/Generic.ASMalwS.1B7119B
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Vigorf.A
ArcabitTrojan.PonyStealer.ED22DCD
AegisLabTrojan.Win32.Onion.j!c
GDataGen:Heur.PonyStealer.4m0@eywcMhpb
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeGeneric.akb
MAXmalware (ai score=100)
VBA32Hoax.Onion
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CTBLOCKER.C
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!upWMSRmvqus
IkarusTrojan-Ransom.CTB-Locker
FortinetW32/GenKryptik.EHBD!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Injector.CXHD?

Win32/Injector.CXHD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment