Malware

Should I remove “Win32/Injector.DERS”?

Malware Removal

The Win32/Injector.DERS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DERS virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.DERS?


File Info:

crc32: 81032679
md5: f1bb71c744320899ddd77e871529413a
name: F1BB71C744320899DDD77E871529413A.mlw
sha1: 2861516dd627f9dbc540308cc0fc4cd248e14fd6
sha256: dd840dc77d44458757d54ef4dce9f4f03d172d3a822a7c8471a248bdb7de9832
sha512: 2265a3127c6a8dd840155e8b63bc9b12a28463b159be26da85f71da429bfbebde7b4662fc662e5df3d4f4d861e02446a92a112d26405d1cfcb62ed97260fcd44
ssdeep: 6144:6IT70CysbEoXgoZbrd+KyHSkToVqGVacCPLJRZ:6ITIvAbLh+KyHSkTGqGVa3/Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: AirDrone
FileVersion: 3.03.0004
CompanyName: XMedia Recode..
Comments: Vallet
ProductName: Vallet
ProductVersion: 3.03.0004
FileDescription: Vallet
OriginalFilename: AirDrone.exe

Win32/Injector.DERS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.mm0@c0aFbpki
FireEyeGeneric.mg.f1bb71c744320899
McAfeeArtemis!F1BB71C74432
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f7b1b1 )
BitDefenderGen:Heur.PonyStealer.mm0@c0aFbpki
K7GWTrojan ( 004f7b1b1 )
Cybereasonmalicious.744320
BitDefenderThetaGen:NN.ZevbaF.34804.mm0@a0aFbpki
CyrenW32/Injector.GH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DERS
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Injector.f5c77f02
NANO-AntivirusTrojan.Win32.DERF.ekzjqx
RisingTrojan.Injector!1.B459 (CLASSIC)
Ad-AwareGen:Heur.PonyStealer.mm0@c0aFbpki
SophosML/PE-A + Mal/FareitVB-I
ComodoMalware@#7g89bpl7vcb0
F-SecureHeuristic.HEUR/AGEN.1112795
ZillyaTrojan.Injector.Win32.472674
TrendMicroTSPY_HPLOKI.SMVBA
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
EmsisoftGen:Heur.PonyStealer.mm0@c0aFbpki (B)
IkarusTrojan.VB.Crypt
AviraHEUR/AGEN.1112795
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.PonyStealer.E62F2D
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Heur.PonyStealer.mm0@c0aFbpki
CynetMalicious (score: 100)
VBA32BScope.Trojan.Dynamer
ALYacGen:Heur.PonyStealer.mm0@c0aFbpki
MalwarebytesTrojan.VBCrypt
TrendMicro-HouseCallTSPY_HPLOKI.SMVBA
TencentWin32.Trojan.Inject.Auto
YandexTrojan.GenAsa!tb6TC5XJSH8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DKNS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.9C3D.Malware.Gen

How to remove Win32/Injector.DERS?

Win32/Injector.DERS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment