Malware

Should I remove “Win32/Injector.DOUG”?

Malware Removal

The Win32/Injector.DOUG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DOUG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

sirgeneral101.ddns.net

How to determine Win32/Injector.DOUG?


File Info:

crc32: FF47A86E
md5: 1c1607e183cfcdde9fb0fca635c57480
name: 1C1607E183CFCDDE9FB0FCA635C57480.mlw
sha1: 26e54333c15bdf00057c73823cc473d2367e8022
sha256: 3ae49a2339dd1eada034230fb691dd2c9c5addf29e6d7c66202ddea7f541bcd6
sha512: f9a5e8c6fea54d2521b6a08a446d2ec755570061280e262690a3c25b11b4cc91c1fb56c98c741c0b39a88352d8dd8be23fb50b9222fe1daf256f577d0f41e3f4
ssdeep: 24576:O5M2mDYn7dWpErFGdjVBDoLBSdetO+juGU1Vrt4H5tV:O5M2mgWpc8jMFSdet/j7+tex
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.DOUG also known as:

MicroWorld-eScanGen:Trojan.Heur3.LPT.THW@aiuMOMncb
McAfeeGenericRXEA-MI!1C1607E183CF
CylanceUnsafe
SangforMalware
Cybereasonmalicious.183cfc
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Worm.Win32.Generic
BitDefenderGen:Trojan.Heur3.LPT.THW@aiuMOMncb
Ad-AwareGen:Trojan.Heur3.LPT.THW@aiuMOMncb
SophosTroj/Agent-AJFK
DrWebTrojan.DownLoader25.2505
InvinceaTroj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Filetour.th
EmsisoftGen:Trojan.Heur3.LPT.THW@aiuMOMncb (B)
JiangminWorm.Generic.daz
AviraHEUR/AGEN.1128752
MAXmalware (ai score=84)
ArcabitTrojan.Heur3.LPT.E03A33
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Worm.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bcex.C2011395
ALYacGen:Trojan.Heur3.LPT.THW@aiuMOMncb
MalwarebytesTrojan.MalPack.SMY
ESET-NOD32a variant of Win32/Injector.DOUG
YandexTrojan.GenAsa!1LtRbZ3nidw
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/GenKryptik.DPIE!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Injector.DOUG?

Win32/Injector.DOUG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment