Malware

About “Win32/Injector.CYLT” infection

Malware Removal

The Win32/Injector.CYLT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CYLT virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
dl.dropbox.com

How to determine Win32/Injector.CYLT?


File Info:

crc32: 85F90C1D
md5: d61911ef3c4594004f14502041211ebd
name: D61911EF3C4594004F14502041211EBD.mlw
sha1: 5b00a28894ecb1d695428c165fff7b82d85370d8
sha256: 210e90143acc6e3fcd8c225d9c13a48a555832f3818c6f43065267b57f8442e8
sha512: 21d2adbd3041e88e3c26121b34f140dd2224d67a4b616806ccfff651e25fa1084e22b8523e9caac8e0430db91dbfe71d5dc5626ac5285c49108edeac28aa546e
ssdeep: 24576:pCHDluc5gLnhhMZy2pcbXIpr3MI0wEPjE5NBxCxpwojX8zhoJ5cug4Ti0xbUQdY:I4cUz2ppImnPoHJ57H3dYab33MQD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Holocene Gregg Liverpudlian Thoreau Geminid
InternalName: usfs
FileVersion: 8.05.0006
CompanyName: Helmholtz Ramo Winnipeg Thrace
Comments: Giovanni Marceau Alex Thoreau Israelite
ProductName: Trudy Gustave
ProductVersion: 8.05.0006
FileDescription: Catherwood Clio Utrecht Montague
OriginalFilename: usfs.exe

Win32/Injector.CYLT also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
DrWebTrojan.DownLoader21.45598
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.217922
CylanceUnsafe
ZillyaTrojan.Injector.Win32.414535
SangforTrojan.Win32.Injector.8
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/VBKrypt.c13863f9
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.f3c459
CyrenW32/VBInject.1!Generic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CYLT
APEXMalicious
AvastWin32:Cambot-O [Trj]
KasperskyTrojan.Win32.VBKrypt.epyd
BitDefenderGen:Variant.Ursu.217922
NANO-AntivirusTrojan.Win32.Crypted.ecifhk
MicroWorld-eScanGen:Variant.Ursu.217922
TencentWin32.Trojan.Vbkrypt.Wozh
Ad-AwareGen:Variant.Ursu.217922
SophosML/PE-A
ComodoMalware@#njfd6c5j3ph2
BitDefenderThetaGen:NN.ZevbaF.34294.@p0@aihCaugi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot.gen.bbp
FireEyeGeneric.mg.d61911ef3c459400
EmsisoftGen:Variant.Ursu.217922 (B)
JiangminTrojan.VBKrypt.ajxo
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.Ursu.D35342
GDataGen:Variant.Ursu.217922
McAfeeArtemis!D61911EF3C45
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
RisingTrojan.Generic@ML.97 (RDML:PUAhIkB9LI/rpBND/+cNiw)
YandexTrojan.GenAsa!U/dzbL6Ge3M
IkarusTrojan.Win32.VBKrypt
FortinetW32/VBKrypt.EPYD!tr
AVGWin32:Cambot-O [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.CYLT?

Win32/Injector.CYLT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment