Malware

WinGo/Injector.K removal instruction

Malware Removal

The WinGo/Injector.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WinGo/Injector.K virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine WinGo/Injector.K?


File Info:

name: 073DCFB68C71335D30F3.mlw
path: /opt/CAPEv2/storage/binaries/dd62783845b8f23c6e95581a1c44b42bbce7f79c3c6be673cef2873373f0ddf9
crc32: E320539A
md5: 073dcfb68c71335d30f30c6180551450
sha1: 50e54965969215dce78d5e07cd83c2d57b917010
sha256: dd62783845b8f23c6e95581a1c44b42bbce7f79c3c6be673cef2873373f0ddf9
sha512: bc688b0b7f108ba55127b6c7414021be151f5f9bffd7925edd87e77b27f77d8ff4b06db64f0464e1cc45a37f2af74f5e66c58e16864482b35b6e4a2360781526
ssdeep: 12288:eKVpkiA+mg0ow06xdSAjv29cg4LjDa0SHKh/4baFpmgDhQABEtrvF25S7lh1eT:ekXzSxdS0e9V4w9pgDhQAaqS7D1w
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1D1654B03BCE160B9C1BAD2338A65B2A17B31B459073123C72B51A6FE9F76BD41E78354
sha3_384: b29dd6ed59798fd55a1a8783454cae1e7d131b1e28939193e291ada90ef6d4aff53a21fb709a95e309e9331ed90a8e0b
ep_bytes: e97bc3ffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

WinGo/Injector.K also known as:

MicroWorld-eScanTrojan.GenericKD.47500350
ALYacTrojan.GenericKD.47500350
CylanceUnsafe
AlibabaTrojan:Win32/Injector.354e4489
SymantecTrojan.Gen.2
ESET-NOD32a variant of WinGo/Injector.K
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generickdz-9882335-0
BitDefenderTrojan.GenericKD.47500350
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.47500350
SophosMal/Generic-S
DrWebBackDoor.CobaltStrike.2
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.47500350
EmsisoftTrojan.GenericKD.47500350 (B)
IkarusTrojan.WinGo.Rozena
AviraTR/Redcap.zgzpc
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataTrojan.GenericKD.47500350
CynetMalicious (score: 100)
McAfeeArtemis!073DCFB68C71
eGambitUnsafe.AI_Score_62%
FortinetW32/PossibleThreat
AVGWin64:Trojan-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove WinGo/Injector.K?

WinGo/Injector.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment