Malware

About “Win32/Injector.CXRB” infection

Malware Removal

The Win32/Injector.CXRB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CXRB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Injector.CXRB?


File Info:

name: B0FB8E08349EBC6227C1.mlw
path: /opt/CAPEv2/storage/binaries/d14243a8a3260c8e3655031339b02a40b4e7a8ba45e5a36764602904ff3243df
crc32: 59D67F73
md5: b0fb8e08349ebc6227c1f42cb3cf60b0
sha1: 55a6f897c2842a6821f4693451944b63c76ea63c
sha256: d14243a8a3260c8e3655031339b02a40b4e7a8ba45e5a36764602904ff3243df
sha512: e255123466afd8bd21a048eb66a7032cf346a2fa06153da9eb17412dc32b506756ce61a6a734d3e4bf616457831e3c23fa104c852fa70aee0e422ccbdc539544
ssdeep: 6144:RmUpaAQM2fcq6ejZnM/4kNgsgnNta9cdn30UAjbvwrMyAP9xGFr7jFCp:RsbM2fc1gWcMHvP9kD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10874AE15AE00C135E7D503B546BACAADE5BC6E3403D824CFEAA8B8B662351D33D3355E
sha3_384: e887fe6928a94a95a14642c2979bdead6cc77864ebcc75e9b5daab851c25222f290f6ff0476dc1981836a19bf005acf7
ep_bytes: 558bec6aff6838ae410068089e400064
timestamp: 2016-05-01 22:08:08

Version Info:

0: [No Data]

Win32/Injector.CXRB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.11574
MicroWorld-eScanGen:Heur.Mint.Titirez.vqW@IKvQQfoc
FireEyeGeneric.mg.b0fb8e08349ebc62
CAT-QuickHealRansomware.Tescrypt.WR5
ALYacGen:Heur.Mint.Titirez.vqW@IKvQQfoc
CylanceUnsafe
ZillyaTrojan.Injector.Win32.391687
SangforTrojan.Win32.Injector.8
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/Vimbed.8918f822
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.8349eb
BitDefenderThetaGen:NN.ZexaF.34084.vqW@aKvQQfoc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CXRB
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vimbed.eb
BitDefenderGen:Heur.Mint.Titirez.vqW@IKvQQfoc
NANO-AntivirusTrojan.Win32.Steam.edzjfe
AvastWin32:Crypt-SMF [Trj]
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Heur.Mint.Titirez.vqW@IKvQQfoc
SophosMal/Generic-R + Mal/CerberW-A
BaiduWin32.Trojan.Cerber.b
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Heur.Mint.Titirez.vqW@IKvQQfoc (B)
IkarusTrojan.Win32.Kovter
GDataGen:Heur.Mint.Titirez.vqW@IKvQQfoc
AviraTR/AD.BetaBot.Y.ahju
Antiy-AVLTrojan/Generic.ASMalwS.1853C30
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2158724
Acronissuspicious
McAfeeArtemis!B0FB8E08349E
VBA32BScope.Adware.Lollipop
APEXMalicious
RisingTrojan.Generic@ML.97 (RDML:2c4Adp1ndwhx74GxmxA8gg)
YandexTrojan.Injector!iT5da4NMeKI
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.2E50AE!tr
AVGWin32:Crypt-SMF [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.CXRB?

Win32/Injector.CXRB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment