Malware

Win32/Injector.DFJI removal guide

Malware Removal

The Win32/Injector.DFJI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DFJI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.DFJI?


File Info:

name: 60F0A9453E8F50BFB091.mlw
path: /opt/CAPEv2/storage/binaries/ddd370637f58b7e3e08964464e021032b4270f084c864bf1cc785d75ffb33d71
crc32: E5859D3A
md5: 60f0a9453e8f50bfb0912d647861ec9d
sha1: 4d03838e32713d2b9376b065cc059180019aa933
sha256: ddd370637f58b7e3e08964464e021032b4270f084c864bf1cc785d75ffb33d71
sha512: 8b9079361e27d9fb1b6924595dbe154c8138864ca67eb1e53cb3f8048c1390543c47e51c198bddaed4872c13517bae9f3c15409631731b015f6823a8e773dac9
ssdeep: 6144:tBkyKkR1YOsyrvwPv3z9EbWjCY1PiiLz3Tv3ow1FCL5:byOSjCY4i/j1F2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD94AD17C3269813F7B48EF5461645A5008E9CEEF8325C3532EBEDBECB298A95071379
sha3_384: 735c8512922be221dcdfc50c4d3b0fdc018b8c083e632fb03b2accd4e60ab5597056430cb535bd189f3a129a819c486a
ep_bytes: 6898414600e8eeffffff000000000000
timestamp: 2016-09-21 04:55:23

Version Info:

Translation: 0x0410 0x04b0
CompanyName: BrFac
ProductName: BrFac
FileVersion: 5.06.0007
ProductVersion: 5.06.0007
InternalName: Galbahar3
OriginalFilename: Galbahar3.exe

Win32/Injector.DFJI also known as:

LionicTrojan.Win32.Zbot.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.Bm0@cGnVbtaG
FireEyeGeneric.mg.60f0a9453e8f50bf
McAfeeFareit-FQV!60F0A9453E8F
CylanceUnsafe
VIPREGen:Heur.PonyStealer.Bm0@cGnVbtaG
SangforTrojan.Win32.Zbot.xdlu
K7AntiVirusTrojan ( 004f8f991 )
AlibabaTrojanSpy:Win32/Injector.d6464774
K7GWTrojan ( 004f8f991 )
Cybereasonmalicious.53e8f5
CyrenW32/VBInject.HR.gen!Eldorado
SymantecInfostealer.Limitail
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.DFJI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Zbot-6907474-0
KasperskyTrojan-Spy.Win32.Zbot.xdlu
BitDefenderGen:Heur.PonyStealer.Bm0@cGnVbtaG
NANO-AntivirusTrojan.Win32.AD.egstmg
AvastWin32:Malware-gen
RisingMalware.Undefined!8.C (TFE:4:4KR0A7gJncC)
Ad-AwareGen:Heur.PonyStealer.Bm0@cGnVbtaG
SophosML/PE-A + Troj/Zbot-LJK
ZillyaTrojan.Zbot.Win32.198144
TrendMicroTROJ_FRS.0NA000IM16
McAfee-GW-EditionFareit-FQV!60F0A9453E8F
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.PonyStealer.Bm0@cGnVbtaG (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.PonyStealer.Bm0@cGnVbtaG
JiangminTrojanSpy.Zbot.fgpx
WebrootW32.Trojan.GenKD
GoogleDetected
AviraHEUR/AGEN.1206733
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Zbot.xd.(kcloud)
ArcabitTrojan.PonyStealer.ED43A1
MicrosoftTrojan:Win32/Ditertag.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
VBA32TScope.Trojan.VB
ALYacGen:Heur.PonyStealer.Bm0@cGnVbtaG
MAXmalware (ai score=100)
TrendMicro-HouseCallTROJ_FRS.0NA000IM16
TencentMalware.Win32.Gencirc.114b38f4
YandexTrojan.GenAsa!pqUHrHv8mPY
IkarusTrojan.VB.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.EHT!tr
BitDefenderThetaGen:NN.ZevbaF.34754.Bm0@aGnVbtaG
AVGWin32:Malware-gen
PandaTrj/Agent.GCC

How to remove Win32/Injector.DFJI?

Win32/Injector.DFJI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment