Malware

Win32/Injector.DGXX (file analysis)

Malware Removal

The Win32/Injector.DGXX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DGXX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Loads a driver
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
vv.video.qq.com
jmcchd.jmcchd.xyz
tiebapic.baidu.com
a.tomx.xyz
ip.taobao.com
ip.chinaz.com
pv.sohu.com
api.wees.xyz
api.abbtv.xyz

How to determine Win32/Injector.DGXX?


File Info:

crc32: 567DA8B1
md5: 0a3ce5419ab0f729d99e3c289a633953
name: whserver.exe
sha1: 0be0112451c9c96ea756693f813c6fb5621550fc
sha256: 0ed603b6be770052c39e7994744616b92765f1b883646310ee62bb1ba08c184d
sha512: acdebd4644e4421390a175a2c36fd0da9458a2d7454eca29099609c0935656772489739e822adda1fed9bd0e2366f9997d9ce22d1fb7f2189488e6e8229f8891
ssdeep: 12288:pzCKMMrYVdDROnaAy5IR8C/80yKLi2goigNHOOlxQY/:hCKM3EaAy5IeKgoir9gNHp/x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.DGXX also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Trojan.Heur.GZ.GyW@b01CMxk
FireEyeGeneric.mg.0a3ce5419ab0f729
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Trojan.Heur.GZ.GyW@b01CMxk
Cybereasonmalicious.19ab0f
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataGen:Trojan.Heur.GZ.GyW@b01CMxk
KasperskyUDS:DangerousObject.Multi.Generic
TencentWin32.Trojan.Gen.Eym
Endgamemalicious (high confidence)
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureHeuristic.HEUR/AGEN.1107272
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.GZ.GyW@b01CMxk (B)
AviraHEUR/AGEN.1107272
MAXmalware (ai score=86)
ArcabitTrojan.Heur.GZ.EC785A
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Malware/Win32.RL_Generic.R325091
Acronissuspicious
VBA32BScope.Backdoor.Androm
Ad-AwareGen:Trojan.Heur.GZ.GyW@b01CMxk
ESET-NOD32a variant of Win32/Injector.DGXX
RisingTrojan.Blamon!8.E8FB (TFE:dGZlOgV6QzVctRmk9A)
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaAI:Packer.563BAD811E
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM16.0.3756.Malware.Gen

How to remove Win32/Injector.DGXX?

Win32/Injector.DGXX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment