Malware

About “Win32/Injector.DEFC” infection

Malware Removal

The Win32/Injector.DEFC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DEFC virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

How to determine Win32/Injector.DEFC?


File Info:

crc32: 928F7D9B
md5: 1525f5b1216e0325e8d4fe809100b0e8
name: 1525F5B1216E0325E8D4FE809100B0E8.mlw
sha1: 8b6dc6d22cecfa81ccd55145f77d7d7ac6d8c60c
sha256: 87478e2c36ffebb4a487d36d99edeb6ae1c281a614394972e9686cf0df0570ac
sha512: 3ce6cd33a3ade945850b5fbc47418819ebc499b4e9606728a9105fd25f441ea90a0714a2261faf9e00d6d591426db7ac485d6b88200e5e5816eec320c87549cd
ssdeep: 24576:9VFLetu5/E3QeUA1kAmf+3FjzkFboLgA9j:zFLety/bM1Dmf2jzkFboLggj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: AfterSun
InternalName: AfterSun
FileVersion: 1.00
CompanyName: Quick Heal Technologies Pvt. Ltd...
LegalTrademarks: AfterSun
ProductName: AfterSun
ProductVersion: 1.00
FileDescription: AfterSun
OriginalFilename: AfterSun.exe

Win32/Injector.DEFC also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Tordev.976
MicroWorld-eScanGen:Heur.PonyStealer.Ym0@eO5WNUki
FireEyeGeneric.mg.1525f5b1216e0325
ALYacGen:Heur.PonyStealer.Ym0@eO5WNUki
MalwarebytesTrojan.MalPack.VB
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 004f6cc51 )
BitDefenderGen:Heur.PonyStealer.Ym0@eO5WNUki
K7GWTrojan ( 004f6cc51 )
Cybereasonmalicious.1216e0
TrendMicroTSPY_HPFAREIT.SMC
BitDefenderThetaGen:NN.ZevbaF.34634.Ym0@aO5WNUki
CyrenW32/VBKrypt.YU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.HawkEye-7722828-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.51e204e0
ViRobotTrojan.Win32.Z.Ponystealer.831488.A
TencentMalware.Win32.Gencirc.11b1385d
Ad-AwareGen:Heur.PonyStealer.Ym0@eO5WNUki
SophosMal/FareitVB-G
ComodoMalware@#3men3ug48i1t0
F-SecureHeuristic.HEUR/AGEN.1119930
InvinceaML/PE-A + Mal/FareitVB-G
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
EmsisoftGen:Heur.PonyStealer.Ym0@eO5WNUki (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bsmlx
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1119930
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftPWS:Win32/Fareit!ml
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.PonyStealer.E27E26
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.PonyStealer.Ym0@eO5WNUki
CynetMalicious (score: 85)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeGenericRXAA-AA!1525F5B1216E
MAXmalware (ai score=85)
VBA32TScope.Trojan.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DEFC
TrendMicro-HouseCallTSPY_HPFAREIT.SMC
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.Agent!Tepdge/Ic7w
IkarusTrojan.Win32.Injector
FortinetW32/Injector.CXGE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.61e

How to remove Win32/Injector.DEFC?

Win32/Injector.DEFC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment