Malware

Win32/Injector.DPAH information

Malware Removal

The Win32/Injector.DPAH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DPAH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
aimware.net
a.tomx.xyz

How to determine Win32/Injector.DPAH?


File Info:

crc32: FD271D5D
md5: 5823e217af3809686124f8d72dc4afc0
name: 6fgoua1.exe
sha1: ed74c56f59d4ac34e34b92fe4a21fe939d6cb3fa
sha256: 644ae0453c6c9f083d31c4d2c382e32ec625d2821203afddf9ddd9733e80934f
sha512: cb6ebbfaaf640a9fd6030c65f82f98d5e6875a6398f4350d81f38b64d659055c94ddcf3c1acedcb90da2637e8578052c9619986a2591382f3e23fc41fa2a9dba
ssdeep: 49152:giioynhwpyUDa2KAy2KJPxyBszhySY3L+7z1N3YLNNUUL:jioynGpyUubJKzS6L+z1FYLNTL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.DPAH also known as:

MicroWorld-eScanGen:Trojan.Heur.GZ.sgW@bu!BpDi
McAfeePacked-VO!5823E217AF38
K7GWTrojan ( 00511eae1 )
K7AntiVirusTrojan ( 00511eae1 )
TrendMicroMal_MLWR-1
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9999
SymantecTrojan.Gen
TrendMicro-HouseCallMal_MLWR-1
AvastWin32:Evo-gen [Susp]
GDataGen:Trojan.Heur.GZ.sgW@bu!BpDi
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.GZ.sgW@bu!BpDi
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.Z.Injector.2405888.G
AegisLabTroj.W32.Generic!c
RisingTrojan.Injector!1.AF22 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.Heur.GZ.sgW@bu!BpDi (B)
ComodoTrojWare.Win32.VirRansom.A
F-SecureGen:Trojan.Heur.GZ.sgW@bu!BpDi
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VirRansom.vc
SophosMal/Behav-238
SentinelOnestatic engine – malicious
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Heur.GZ.ED166D4
ZoneAlarmHEUR:Trojan.Win32.Generic
Ad-AwareGen:Trojan.Heur.GZ.sgW@bu!BpDi
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.DPAH
TencentWin32.Trojan.Generic.Sunr
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DPAH!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.1b8fb7
Paloaltogeneric.ml
CrowdStrikemalicious_confidence_100% (W)
Qihoo-360Win32/Trojan.03f

How to remove Win32/Injector.DPAH?

Win32/Injector.DPAH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment