Malware

Win32/Injector.DHJR removal tips

Malware Removal

The Win32/Injector.DHJR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DHJR virus can do?

  • Presents an Authenticode digital signature
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.DHJR?


File Info:

crc32: 3328DA14
md5: aea383a0567f5f95aba618d6ccc03b36
name: AEA383A0567F5F95ABA618D6CCC03B36.mlw
sha1: 71976feb1db6d908d153b58f8eece5fae6b157c2
sha256: 475dafe73a46bd8d501753383e1e3cd9ef5284832ca6133f7b5b80b7f6bcd9c5
sha512: 41e25d4409fa188913127d1500ce0778a12e6ef0eaa7635d79b8230e09666b8a29819c83930972330b7efafdafda207da43c6451ad06e5f264642c4f9837e36f
ssdeep: 12288:tnzHcMHESf1Ai4y1zasdVgcQzH2UHESf1A6IIzgezDewL07Qg1Vmy4Ccr:tzLV9AMuDcy1V9AQgooh1cFCy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Trince
FileVersion: 1.01.0006
CompanyName: HoFAectifys
Comments: Junctional3
ProductName: Distilland
ProductVersion: 1.01.0006
FileDescription: Hilton Hotels
OriginalFilename: Trince.exe

Win32/Injector.DHJR also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.zo2@e0BYtQii
FireEyeGeneric.mg.aea383a0567f5f95
CAT-QuickHealTrojan.MSIL
Qihoo-360HEUR/QVM03.0.3967.Malware.Gen
McAfeeFareit-FHG!AEA383A0567F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Heur.PonyStealer.zo2@e0BYtQii
Cybereasonmalicious.0567f5
TrendMicroTSPY_HPFAREIT.SME
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.NetWire-7724399-0
KasperskyTrojan.MSIL.Crypt.dfml
RisingTrojan.Injector!1.B459 (CLASSIC)
Ad-AwareGen:Heur.PonyStealer.zo2@e0BYtQii
EmsisoftGen:Heur.PonyStealer.zo2@e0BYtQii (B)
F-SecureHeuristic.HEUR/AGEN.1113477
DrWebTrojan.DownLoader35.12902
InvinceaML/PE-A
McAfee-GW-EditionFareit-FHG!AEA383A0567F
JiangminTrojan.MSIL.rmin
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1113477
MAXmalware (ai score=84)
Antiy-AVLTrojan/MSIL.Crypt
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.PonyStealer.E6BCF4
ZoneAlarmTrojan.MSIL.Crypt.dfml
GDataGen:Heur.PonyStealer.zo2@e0BYtQii
CynetMalicious (score: 85)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
BitDefenderThetaGen:NN.ZevbaF.34590.zo2@a0BYtQii
ALYacGen:Heur.PonyStealer.zo2@e0BYtQii
VBA32TScope.Trojan.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DHJR
TrendMicro-HouseCallTSPY_HPFAREIT.SME
YandexTrojan.Crypt!/KcwTfpMoZA
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.DPDX!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.11003490.susgen

How to remove Win32/Injector.DHJR?

Win32/Injector.DHJR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment