Malware

Win32/Injector.DHJX (file analysis)

Malware Removal

The Win32/Injector.DHJX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DHJX virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed analysis tools by a known file location
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects Sandboxie using a known mutex
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a device
  • Detects VMware through the presence of a registry key
  • Detects Virtual PC using a known mutex
  • Attempts to modify proxy settings
  • Checks for a known DeepFreeze Frozen State Mutex
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
dosyakylachkova1.com
fofancanada2017.com
pisyasisyadot.com

How to determine Win32/Injector.DHJX?


File Info:

crc32: 8A48532A
md5: 78503aa97f84d8871a015ecc2516a8f7
name: 78503AA97F84D8871A015ECC2516A8F7.mlw
sha1: 9fbad8dc6ac4f20c0c92ae9b46d97c688a5d0fc4
sha256: e01508b1b3a858b53d5c0fac4a836d4280e5195be7f5130d55b373cf334ee2b5
sha512: a39e002f7a8140fd32e73fca9322a51fe24b307c4720176536bef580fc1470733f693a164feea61bc5e8b276c79b56c3ce5a96bcd6876dca4a8112bf4e212447
ssdeep: 3072:/47VxR/9v9bgXRC4nDIGeQfKDTU6jfpgJn6dssE:g7ZFdg7IOKU6jMn6dV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.DHJX also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillProc.48212
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
ZillyaTrojan.Injector.Win32.432639
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0055e3991 )
K7AntiVirusTrojan ( 0055e3991 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DHJX
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.KillProc.ewvalr
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentMalware.Win32.Gencirc.114b5676
Ad-AwareTrojan.BRMon.Gen.4
SophosML/PE-A + Troj/Inject-CEC
BitDefenderThetaGen:NN.ZexaF.34170.juZ@aWAqxQae
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_Virus
McAfee-GW-EditionPWSZbot-FAXK!78503AA97F84
FireEyeGeneric.mg.78503aa97f84d887
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.tel
AviraHEUR/AGEN.1100844
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Generic.ASMalwS.1C6E6E6
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.BRMon.Gen.4
McAfeePWSZbot-FAXK!78503AA97F84
MAXmalware (ai score=98)
VBA32Worm.Palevo
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/CI.A
TrendMicro-HouseCallPossible_Virus
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!xXXG5V2GtuQ
IkarusTrojan.Win32.Derbit
FortinetW32/Generic.AP.29087!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DHJX?

Win32/Injector.DHJX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment