Malware

Win32/Injector.DNQB removal tips

Malware Removal

The Win32/Injector.DNQB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DNQB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Hebrew
  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.DNQB?


File Info:

crc32: 5A12CC99
md5: 99b41357409d45f6375d61439dfa2d38
name: 99B41357409D45F6375D61439DFA2D38.mlw
sha1: 64577fd715a502376003df81350fb327eca582a4
sha256: de5ed6cb5eca4c436665066febc925a70ca176d259a5db82af04f07b363bba9b
sha512: 5ebcae552a55ad6875bcb7f313b54d8ca2dce864fc62616c45fb95a1c9d553b9d396ace987fa4e74e55216eae7224f144cbdd4db0fde91e85e803d8e1304b573
ssdeep: 6144:6IBWg4q6KcE/5wZIceKy1lGqgKMjymrAxzS2eU2NqAjKOWMOz:6IB+5KvxwZIceTHg7+YAxzOshZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x040d 0x04b0
InternalName: dwedfgzrsw4
FileVersion: 2.07.0005
CompanyName: Fitpay
Comments: Brevsamlingsstedernes5
ProductName: Megadynamics
ProductVersion: 2.07.0005
OriginalFilename: dwedfgzrsw4.exe

Win32/Injector.DNQB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.wm0@bOL1!skG
FireEyeGeneric.mg.99b41357409d45f6
McAfeePacked-KC!99B41357409D
CylanceUnsafe
VIPRELooksLike.Win32.Malware!vb (v)
SangforMalware
K7AntiVirusTrojan ( 0050b0211 )
BitDefenderGen:Heur.PonyStealer.wm0@bOL1!skG
K7GWTrojan ( 0050b0211 )
Cybereasonmalicious.7409d4
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyTrojan-Spy.Win32.Zbot.ydgy
NANO-AntivirusTrojan.Win32.Zbot.enptrm
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Heur.PonyStealer.wm0@bOL1!skG
EmsisoftGen:Heur.PonyStealer.wm0@bOL1!skG (B)
F-SecureHeuristic.HEUR/AGEN.1112794
DrWebTrojan.PWS.Panda.10359
TrendMicroTSPY_FAREIT.AUSINP
McAfee-GW-EditionPacked-KC!99B41357409D
SophosML/PE-A + Mal/FareitVB-M
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VBKrypt.dnzx
AviraHEUR/AGEN.1112794
MAXmalware (ai score=87)
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Zbot!CI
ArcabitTrojan.PonyStealer.ED4A62
ZoneAlarmTrojan-Spy.Win32.Zbot.ydgy
GDataGen:Heur.PonyStealer.wm0@bOL1!skG
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
BitDefenderThetaGen:NN.ZevbaF.34804.wm0@aOL1!skG
ALYacGen:Heur.PonyStealer.wm0@bOL1!skG
VBA32TScope.Trojan.VB
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DNQB
TrendMicro-HouseCallTSPY_FAREIT.AUSINP
TencentMalware.Win32.Gencirc.10bb7aa9
YandexTrojan.GenAsa!1D9BUFkb3+o
IkarusTrojan-Spy.VB.Agent
eGambitUnsafe.AI_Score_100%
FortinetW32/GenKryptik.ACTV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Spy.a06

How to remove Win32/Injector.DNQB?

Win32/Injector.DNQB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment