Malware

Win32/Injector.DPSO malicious file

Malware Removal

The Win32/Injector.DPSO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DPSO virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

energyrecovry.com

How to determine Win32/Injector.DPSO?


File Info:

crc32: 1D5A8076
md5: 535b1e1bbae14a3eb83d09e46578bede
name: 535B1E1BBAE14A3EB83D09E46578BEDE.mlw
sha1: 3c18fc5f5c16e3733691bb308dcf53a373269ff9
sha256: de4c53a9dbc261be530d38de49f6f81f2aff2f19a883e10170d30cb8a5a5577c
sha512: c785fe5177bcd455f897f31902f6feb4cd73a0cbb56abb1fce4a8318c6d36bac257b52bcba68598e1a0d921b076a21d4466411f0325a874b783cdac3ce02d3b6
ssdeep: 3072:N7mcZ3A6HJKBvHC9jNKl/SS1gng0XLMO:N7vA6HJKBvH0NMSS1gg0X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Isen
InternalName: Lucences
FileVersion: 2.06.0001
CompanyName: Etpsom
LegalTrademarks: Cupride5
ProductName: Schnecke
ProductVersion: 2.06.0001
FileDescription: Legemshjdens2
OriginalFilename: Lucences.exe

Win32/Injector.DPSO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.im0@ceZifImi
FireEyeGeneric.mg.535b1e1bbae14a3e
Qihoo-360Win32/Sorter.AVE.70BackdoorSlider.A
ALYacGen:Heur.PonyStealer.im0@ceZifImi
CylanceUnsafe
AegisLabTrojan.Win32.PonyStealer.4!c
SangforMalware
K7AntiVirusTrojan ( 0051199e1 )
BitDefenderGen:Heur.PonyStealer.im0@ceZifImi
K7GWTrojan ( 0051199e1 )
Cybereasonmalicious.bbae14
BitDefenderThetaGen:NN.ZevbaF.34804.im0@aeZifImi
CyrenW32/Injector.HO2.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DPSO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.VBKryjetor.amxg
AlibabaTrojan:Win32/VBKryjetor.548d092b
NANO-AntivirusTrojan.Win32.VBKryjetor.eqtdcp
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Heur.PonyStealer.im0@ceZifImi
EmsisoftGen:Heur.PonyStealer.im0@ceZifImi (B)
F-SecureTrojan.TR/Dropper.VB.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RB421
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
SophosMal/Generic-R + Mal/FareitVB-M
IkarusTrojan.Win32.Injector
AviraTR/Dropper.VB.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftPWS:Win32/Fareit.AC
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.PonyStealer.ED2F6D
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
ZoneAlarmTrojan.Win32.VBKryjetor.amxg
GDataGen:Heur.PonyStealer.im0@ceZifImi
CynetMalicious (score: 100)
McAfeeArtemis!535B1E1BBAE1
TACHYONTrojan/W32.VB-VBKryjetor.135168
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0RB421
TencentWin32.Trojan.Inject.Auto
YandexTrojan.VBKryjetor!VGCe+HPVgWs
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/GenKryptik.AOBX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.DPSO?

Win32/Injector.DPSO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment