Malware

How to remove “Win32/Injector.DOVE”?

Malware Removal

The Win32/Injector.DOVE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DOVE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.skybusethiopia.com.ng

How to determine Win32/Injector.DOVE?


File Info:

crc32: 2A0FF70F
md5: 031ceff6f7c8ba2a72dcbd7218d90096
name: 031CEFF6F7C8BA2A72DCBD7218D90096.mlw
sha1: 30159e5997808aefaa61a1b347cbbc34dc986724
sha256: dce2d2a347fc8c386de98189f7fcef890099fc71955544b6c656e813b334a6cb
sha512: 1a5b8c311a4ee2fdd15156d0b3382033adbda37e7eb178c511e219f5a7cfaadc2a8180f6d98221c4587b97ca3669a55878936247a478ffc9645ae62af04ad57c
ssdeep: 3072:QPHpnZgUWJb34f56vgCo88CIyDU3VZRB9P00:QvNZ8p4fAvgt8Ch3VZ39Pp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Scout
FileVersion: 9.03.0009
CompanyName: PAnDora tv
Comments: yahOo! inc
ProductName: www.BitdOWnLoader.com
ProductVersion: 9.03.0009
OriginalFilename: Scout.exe

Win32/Injector.DOVE also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.nm0@cKyxwZii
McAfeePacked-KK!031CEFF6F7C8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0050e3b11 )
BitDefenderGen:Heur.PonyStealer.nm0@cKyxwZii
K7GWTrojan ( 0050e3b11 )
Cybereasonmalicious.6f7c8b
BitDefenderThetaGen:NN.ZevbaF.34804.nm0@aKyxwZii
CyrenW32/Injector.HO2.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DOVE
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Dropper.Ponystealer-7552991-0
KasperskyTrojan-PSW.Win32.Fareit.csrc
AlibabaTrojanPSW:Win32/Fareit.6d23a311
NANO-AntivirusTrojan.Win32.Fareit.epfpyw
RisingTrojan.Injector!1.B459 (CLASSIC)
Ad-AwareGen:Heur.PonyStealer.nm0@cKyxwZii
EmsisoftGen:Heur.PonyStealer.nm0@cKyxwZii (B)
ComodoMalware@#3i1he2ryovkqh
F-SecureHeuristic.HEUR/AGEN.1128727
DrWebTrojan.PWS.Stealer.1932
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionPacked-KK!031CEFF6F7C8
FireEyeGeneric.mg.031ceff6f7c8ba2a
SophosML/PE-A + Mal/FareitVB-M
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1128727
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftVirTool:Win32/Injector.FQ
ArcabitTrojan.PonyStealer.ED4FB9
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
ZoneAlarmTrojan-PSW.Win32.Fareit.csrc
GDataGen:Heur.PonyStealer.nm0@cKyxwZii
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.nm0@cKyxwZii
MAXmalware (ai score=87)
VBA32BScope.Trojan.VBKrypt
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
TencentWin32.Trojan.Inject.Auto
YandexTrojan.GenAsa!JGDejgvYyE0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.DOVR!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Injector.DOVE?

Win32/Injector.DOVE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment