Malware

Should I remove “Win32/Injector.DBG”?

Malware Removal

The Win32/Injector.DBG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DBG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Armenian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.DBG?


File Info:

name: 101ED3FAEDE913DF2024.mlw
path: /opt/CAPEv2/storage/binaries/feca7ab9738b4267e3a0f069a60559d7feba681d9e3093f209c85cfe3c45a076
crc32: 116A3C82
md5: 101ed3faede913df20242554ae740f1e
sha1: 27e5927dd2015d9d226f9de54298b1e1925a5a11
sha256: feca7ab9738b4267e3a0f069a60559d7feba681d9e3093f209c85cfe3c45a076
sha512: 0e443fe704575f725e4645731b9c5e1a5282c0231dac769386d1cf1c0f57ccd9617d556c3716985e8e287bd9bcd24869b05f42df817bcdd93a1e602eb4c7c43c
ssdeep: 3072:goenLBbM6mWIpL6kCX1P7C6UpsUUWuNhyRPx6hs8/bAbs:gdmvL8P7CRsUUWuzyRms8T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194B4C50BB680E956C366C4B27A6AE3A821CCFC714144A403FBE19F1B3BB5E99553570F
sha3_384: 7e9af00aa5eac3e35ce233d4ff13ef3032cb92f99aec03768a79ced5a3d4402ddca194869124242f2cdd797eba3443bf
ep_bytes: 6870484000e8eeffffff000048000000
timestamp: 2010-09-21 02:15:58

Version Info:

0: [No Data]

Win32/Injector.DBG also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur.ZGY.5
FireEyeGeneric.mg.101ed3faede913df
McAfeeGenericR-JKT!101ED3FAEDE9
CylanceUnsafe
ZillyaDownloader.VB.Win32.29547
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanDownloader:Win32/Bulta.196ea013
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.254A2CEF15
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.DBG
Paloaltogeneric.ml
ClamAVWin.Trojan.Pakes-9882662-0
KasperskyTrojan-Downloader.Win32.VB.aamx
BitDefenderGen:Trojan.Heur.ZGY.5
NANO-AntivirusTrojan.Win32.VB.bskoe
CynetMalicious (score: 100)
AvastWin32:Trojan-gen
TencentWin32.Trojan-Downloader.Vb.Bgow
Ad-AwareGen:Trojan.Heur.ZGY.5
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.IMspam.12
VIPREGen:Trojan.Heur.ZGY.5
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.ZGY.5 (B)
APEXMalicious
GDataGen:Trojan.Heur.ZGY.5
JiangminTrojanDownloader.VB.czvp
WebrootW32.Malware.Gen
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.9E
ViRobotTrojan.Win32.A.Downloader.442368.V
MicrosoftPWS:Win32/Zbot!ml
GoogleDetected
Acronissuspicious
VBA32Trojan.VBRA.01370
ALYacGen:Trojan.Heur.ZGY.5
MalwarebytesSpyware.PasswordStealer
RisingWorm.Slenping!8.2E04 (TFE:1:R2VhZOg0x4G)
YandexTrojan.GenAsa!Kc+EL2lnWKo
IkarusTrojan.Win32.VBKrypt
FortinetW32/VBInjector.W!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.aede91
PandaGeneric Malware

How to remove Win32/Injector.DBG?

Win32/Injector.DBG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment