Malware

Win32/Injector.CZSD removal

Malware Removal

The Win32/Injector.CZSD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CZSD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.CZSD?


File Info:

crc32: E6350E7F
md5: 802a1c1143d3e2e0244e6f6d4c5ee1c6
name: 802A1C1143D3E2E0244E6F6D4C5EE1C6.mlw
sha1: 7a5fc2c7ea88612f91da64ccd596b651607b78f8
sha256: ddf4423a531a6a03f91a6ff934b0ff95fe3092ac930622b36b89b766fa573535
sha512: b53e1456c3b3d3a0164476e1b3d352f3c09015140806eeac4929f5e23f2996d45ec1e8f401d74122f69e5dacd7d89ef5de385dd1071102e787a4a2065504ccda
ssdeep: 3072:9zId/MMMMM1hhhhhhhhhhhhhhhhhhhhhWXp9y83Y6HMIhU2t:90/MMMMMCZ9PMIh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Anoxybiotic6
FileVersion: 1.00
CompanyName: SYS
ProductName: Roseanna7
ProductVersion: 1.00
FileDescription: Lymphorrhea1
OriginalFilename: Anoxybiotic6.exe

Win32/Injector.CZSD also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.hm0@c4J9kEji
FireEyeGen:Heur.PonyStealer.hm0@c4J9kEji
ALYacGen:Heur.PonyStealer.hm0@c4J9kEji
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f13701 )
BitDefenderGen:Heur.PonyStealer.hm0@c4J9kEji
K7GWTrojan ( 004f13701 )
Cybereasonmalicious.143d3e
BitDefenderThetaGen:NN.ZevbaF.34804.hm0@a4J9kEji
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CZSD
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Fareit-7781709-1
KasperskyTrojan-PSW.Win32.Fareit.cgtx
NANO-AntivirusTrojan.Win32.Fareit.eirtru
RisingTrojan.Dynamer!8.3A0 (CLOUD)
Ad-AwareGen:Heur.PonyStealer.hm0@c4J9kEji
EmsisoftGen:Heur.PonyStealer.hm0@c4J9kEji (B)
ComodoMalware@#1f6gl8j25i25s
DrWebTrojan.PWS.Stealer.19288
TrendMicroBKDR_TOFSEE.SMA
McAfee-GW-EditionFareit-FET!802A1C1143D3
SophosML/PE-A + Mal/FareitVB-F
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1123256
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftPWS:Win32/Zbot!ml
ArcabitTrojan.PonyStealer.E2BD88
SUPERAntiSpywareTrojan.Agent/Gen-VB
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
ZoneAlarmTrojan-PSW.Win32.Fareit.cgtx
GDataGen:Heur.PonyStealer.hm0@c4J9kEji
CynetMalicious (score: 100)
McAfeeFareit-FET!802A1C1143D3
MAXmalware (ai score=86)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallBKDR_TOFSEE.SMA
TencentWin32.Trojan-qqpass.Qqrob.Dwja
YandexTrojan.GenAsa!CJGCA3xqQrw
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.CZSD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/QVM03.0.5642.Malware.Gen

How to remove Win32/Injector.CZSD?

Win32/Injector.CZSD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment