Malware

Win32/Injector.DPJH removal tips

Malware Removal

The Win32/Injector.DPJH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DPJH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

whatismyipaddress.com

How to determine Win32/Injector.DPJH?


File Info:

crc32: 67A18251
md5: 030b7b9b957d3278aa98001137d6d0b8
name: 030B7B9B957D3278AA98001137D6D0B8.mlw
sha1: 486909a37127c88748fd381b4edf5057854c102b
sha256: dda56ca90f58b394e11bcd205a2816067b3da8bc4686873d8b04b9ecf78678ca
sha512: 369073f9b58916e6b9971d788def142e5e0c94db4348c7247843ca6f537a7c658a80a0803e7b76b6b8ef0171377c922caa83fb6aa68eb35423f2e9603031648f
ssdeep: 24576:B1sYUU03emnE6bxT8+PxbuMir5kpOFtTnmHdsCcHEa:B1lzX/sx7qHrqp+tgI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: icQ
InternalName: Ventrimesal
FileVersion: 1.00.0002
LegalTrademarks:
Comments: AvaSt soFTwarE
ProductName: electrUm
ProductVersion: 1.00.0002
FileDescription: captel Sarl
OriginalFilename: Ventrimesal.exe

Win32/Injector.DPJH also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.13025
MicroWorld-eScanGen:Heur.PonyStealer.in0@c4bmsShi
FireEyeGeneric.mg.030b7b9b957d3278
ALYacGen:Heur.PonyStealer.in0@c4bmsShi
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.VBKrypt.4!c
SangforMalware
K7AntiVirusTrojan ( 0050fff31 )
BitDefenderGen:Heur.PonyStealer.in0@c4bmsShi
K7GWTrojan ( 0050fff31 )
Cybereasonmalicious.b957d3
BitDefenderThetaGen:NN.ZevbaF.34804.in0@a4bmsShi
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/VBKrypt.d4953058
NANO-AntivirusTrojan.Win32.VBKrypt.eqemfh
Ad-AwareGen:Heur.PonyStealer.in0@c4bmsShi
EmsisoftGen:Heur.PonyStealer.in0@c4bmsShi (B)
ComodoMalware@#38aukawb1shib
F-SecureHeuristic.HEUR/AGEN.1112802
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
SophosML/PE-A + Mal/FareitVB-M
IkarusTrojan.Win32.Injector
GDataGen:Heur.PonyStealer.in0@c4bmsShi
AviraHEUR/AGEN.1112802
Antiy-AVLTrojan/Win32.VBKrypt
ArcabitTrojan.PonyStealer.ED119EE
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/VBInject.OW!bit
TACHYONTrojan/W32.VB-VBKrypt.1179648.C
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeePacked-MI!030B7B9B957D
MAXmalware (ai score=81)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DPJH
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!22EZ7D3kiCc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.ALGE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Sorter.AVE.70BackdoorSlider.A

How to remove Win32/Injector.DPJH?

Win32/Injector.DPJH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment