Malware

Should I remove “Win32/Injector.DCXF”?

Malware Removal

The Win32/Injector.DCXF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DCXF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

muchcocaugh.com
rutithegde.ru
boropbabrab.ru

How to determine Win32/Injector.DCXF?


File Info:

crc32: 2B895A93
md5: 3129fa7cfa44462c1fcdc3ac3d6278c3
name: 3129FA7CFA44462C1FCDC3AC3D6278C3.mlw
sha1: 0929537e76036fc454bf00e4ddda3b00d19575cf
sha256: 8749911ecda8ccb5056d7b613abb56fcc5fa7c7280e32cbd684c407fd27c44f3
sha512: 2f27f582e7838d5ac40f311beb46e1d16e5e8b4909ff9a2057924b76f0ec9830cda9e3197f7c1979ab55510303f7ca7785f0e186b538d0a676b3b07f42fb3e2f
ssdeep: 3072:88Dsp+FNX1dFOvDlXJufq4TlcIBntNqLcnJrq56DwC884dR1Plc1rwQCJ:88dNXSEfq4TlVntNqMJY6DwC88ecoJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Injector.DCXF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.13052
CynetMalicious (score: 99)
CAT-QuickHealRansom.Onion.A
ALYacTrojan.GenericKD.43374646
ZillyaTrojan.NSIS.Win32.1261
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Enestedel.ff861745
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.cfa444
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.DCXF
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.43374646
NANO-AntivirusTrojan.Win32.Mlw.egcdkk
MicroWorld-eScanTrojan.GenericKD.43374646
TencentWin32.Trojan.Inject.Lfzt
Ad-AwareTrojan.GenericKD.43374646
SophosML/PE-A + Mal/Miuref-L
ComodoMalware@#1dzb8ijviidft
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBERENC.SMNS1
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.cc
FireEyeGeneric.mg.3129fa7cfa44462c
EmsisoftTrojan.GenericKD.43374646 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASSuf.1E387
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D295D836
GDataTrojan.GenericKD.43374646
McAfeeArtemis!3129FA7CFA44
MAXmalware (ai score=82)
VBA32Trojan.Inject
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBERENC.SMNS1
IkarusTrojan.Win32.Injector
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DCXF?

Win32/Injector.DCXF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment