Malware

Win32/Injector.GIK (file analysis)

Malware Removal

The Win32/Injector.GIK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.GIK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Thai
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Injector.GIK?


File Info:

name: CD5B629D2997AA379148.mlw
path: /opt/CAPEv2/storage/binaries/8abd5b03708be9f1332371a037a9526a02c57407a556c84ba2ab985888ad76ee
crc32: AE818CA2
md5: cd5b629d2997aa3791481f441a66ff2b
sha1: 0b13e1979fa23b5cb8a852ae1d114c8e64206b4c
sha256: 8abd5b03708be9f1332371a037a9526a02c57407a556c84ba2ab985888ad76ee
sha512: a0bc9ac158e963ff867d7f516064a0fd07e66773a5376a74f9952374e4da57fe86f5bd25893daf07d2224ed2782964dc84145dfff740f722c57af491d33e5651
ssdeep: 12288:t4h9kc8h7g0+v2HP/RB1Swx46HRROoC77hRTpPpw5vq/W:t4UNZHP/n1Sw9RRe77hRTpPu1p
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172A423A0664775C0E6BF0E70E7AE69971D1FAC1277E232700E3AF6A6743E1C51267E01
sha3_384: 62e9a8ea1390fe7da3db79c7a5404e03e021680aea08b0ea9f3e05bbebc3595d61b4d4015c8b69b5386fc0a98ce0170a
ep_bytes: 60be00b041008dbe0060feff5783cdff
timestamp: 2011-04-21 11:36:13

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Jhejf0Q3
ProductName: BzZumyiSSFdJ
FileVersion: 15.502.0544
ProductVersion: 15.502.0544
InternalName: GovohHYd
OriginalFilename: GovohHYd.exe

Win32/Injector.GIK also known as:

LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (moderate confidence)
DrWebTrojan.PWS.Siggen.28421
MicroWorld-eScanGen:Heur.Spesr.VB.1
FireEyeGeneric.mg.cd5b629d2997aa37
ALYacGen:Heur.Spesr.VB.1
CylanceUnsafe
VIPREGen:Heur.Spesr.VB.1
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
BitDefenderGen:Heur.Spesr.VB.1
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.B191A0111F
SymantecTrojan.Usuge!gen3
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.GIK
TrendMicro-HouseCallWORM_VOBFUS.SMHC
Paloaltogeneric.ml
KasperskyWorm.Win32.VBNA.bghe
AlibabaWorm:Win32/VBInject.531666c9
NANO-AntivirusTrojan.Win32.TrjGen.tlhlm
RisingWorm.VBNA!8.2BE (CLOUD)
Ad-AwareGen:Heur.Spesr.VB.1
SophosML/PE-A + Mal/VBCheMan-A
ComodoMalware@#rps72hf09dk7
ZillyaTrojan.VB.Win32.153313
TrendMicroWORM_VOBFUS.SMHC
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Spesr.VB.1 (B)
IkarusTrojan.Win32.Ramnit
JiangminWorm.VBNA.gtw
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Heur.Spesr.VB.1
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!CD5B629D2997
VBA32Malware-Cryptor.VB.gen
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
APEXMalicious
TencentWin32.Worm.Vbna.Tdkl
SentinelOneStatic AI – Malicious PE
FortinetW32/Refroso.AGEA!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.d2997a
AvastWin32:Trojan-gen

How to remove Win32/Injector.GIK?

Win32/Injector.GIK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment