Malware

Win32/Injector.ZNF removal

Malware Removal

The Win32/Injector.ZNF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ZNF virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Win32/Injector.ZNF?


File Info:

crc32: FDDB29DB
md5: 13bb66e267c18384d52aefe21ce7b346
name: 13BB66E267C18384D52AEFE21CE7B346.mlw
sha1: 0d82f6d5c1f1a5a02251ced67c3224d180274d08
sha256: 13f192cc8f1c5b4cbb894e50e34fdd0ada844fd2a0280459c0189b2e0feac75b
sha512: d70fb4ddaef0f2808a5ad2d6eea5a517d49678d8651cecba55d0891677a16b7c5f692271623f7eb84a28bc4f08ba0e5a7c31d6bef505a2e11276564941c3107f
ssdeep: 3072:bdY0YyGZp6nZpC9A1UZgMbk51eNCkcAt6bCSNpwaPIH+6ZSzqnoVzInPIWIlLAr:K5yGZp6nZpC9A1UZgMbk51eNCkcAt6b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: iqAnZTUSYGOXgML4SWMgOpm1Nc0P6
FileVersion: 856.278.0412
CompanyName: bJ
ProductName: Project1
ProductVersion: 856.278.0412
OriginalFilename: iqAnZTUSYGOXgML4SWMgOpm1Nc0P6.exe

Win32/Injector.ZNF also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Blocker.4!c
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.40116
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.57a82d18
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ZNF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.lday
NANO-AntivirusTrojan.Win32.VP2.ffsfha
TencentWin32.Trojan.Blocker.Dygx
SophosML/PE-A + Mal/VBCheMan-D
ComodoTrojWare.Win32.VBInject.IK@1qsu2f
BitDefenderThetaAI:Packer.0AE13DE620
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.ct
FireEyeGeneric.mg.13bb66e267c18384
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.jbf
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.27172AD
MicrosoftTrojan:Win32/Occamy.C13
McAfeeArtemis!13BB66E267C1
MAXmalware (ai score=100)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBInjector.W!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.ZNF?

Win32/Injector.ZNF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment