Malware

How to remove “Win32/Injector.CYWG”?

Malware Removal

The Win32/Injector.CYWG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CYWG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Win32/Injector.CYWG?


File Info:

name: 31F35B818AC75A29379E.mlw
path: /opt/CAPEv2/storage/binaries/a008ce4eebb6457cecd88455f48fc611ccf3568519c86f243432f77bbc285674
crc32: 715D4323
md5: 31f35b818ac75a29379e98c59fb3d99f
sha1: 0b16679bcad550f98538cbabb27942bd7ec6dd8f
sha256: a008ce4eebb6457cecd88455f48fc611ccf3568519c86f243432f77bbc285674
sha512: 3a66a29f21ef49df1f64821bc892eb725fc7cf4b28bcf3f5cf1d5cbd1221aacd72e898f042ece3459b7b6b07b4ddd8c19aa19c4a12161783893d8d71a6dd9e7c
ssdeep: 12288:oBUj90XI2Xj2PvBe5rTXib7ToWCRqXmZPHZdTvTz1MInWpb2ugMSRzcEsboOjOKd:o5Y2+BetinELRquRTJBnaIBRQEWljxd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1053533A57FC26C21CAB3AD3955142516CDA1FD2068BB8317B3BDBC4D2C66E101B88B87
sha3_384: d88609233fbb6f97c19ea6fc5894365cc3ae3577fa8030b0e23f892b71ac2eeb8519e01301cc744d252110eded7c53ad
ep_bytes: 558bec6a9068b0224000686a19400064
timestamp: 1970-01-14 17:44:42

Version Info:

0: [No Data]

Win32/Injector.CYWG also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.DownLoader21.48576
MicroWorld-eScanTrojan.GenericKDZ.32996
FireEyeGeneric.mg.31f35b818ac75a29
McAfeePWSZbot-FARB!31F35B818AC7
CylanceUnsafe
ZillyaTrojan.Tepfer.Win32.87566
SangforTrojan.Win32.Injector.8
K7AntiVirusTrojan ( 004eff261 )
K7GWTrojan ( 004eff261 )
Cybereasonmalicious.18ac75
BitDefenderThetaGen:NN.ZexaF.34646.azZ@auiRn0H
VirITTrojan.Win32.Generic.IYN
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.CYWG
APEXMalicious
ClamAVWin.Trojan.Razy-7191351-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.32996
NANO-AntivirusTrojan.Win32.BotFARB.ezepxc
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b4ae02
Ad-AwareTrojan.GenericKDZ.32996
EmsisoftTrojan.GenericKDZ.32996 (B)
BaiduWin32.Trojan.Injector.jf
VIPRETrojan.GenericKDZ.32996
TrendMicroTROJ_TOBFY.SM1
McAfee-GW-EditionPWSZbot-FARB!31F35B818AC7
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Zbot-UM
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Tepfer.ctz
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1234097
Antiy-AVLTrojan/Generic.ASMalwS.3C54
MicrosoftBackdoor:Win32/Kelihos
ArcabitTrojan.Generic.D80E4
GDataTrojan.GenericKDZ.32996
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R184677
VBA32Backdoor.Hlux
ALYacTrojan.GenericKDZ.32996
MAXmalware (ai score=82)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_TOBFY.SM1
RisingTrojan.Injector!8.C4 (TFE:1:g1f5YM0zEbN)
YandexTrojan.PWS.Tepfer!v7nCqSIRagY
IkarusTrojan-Downloader.Win32.Bredolab
FortinetW32/Injector.CYYY!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.CYWG?

Win32/Injector.CYWG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment