Malware

Win32/Injector.DQCE removal guide

Malware Removal

The Win32/Injector.DQCE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DQCE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • CAPE detected the TrickBot malware family
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.DQCE?


File Info:

name: 1D1199A4E9824DA0CDA9.mlw
path: /opt/CAPEv2/storage/binaries/7754904ddd9031c47adcf4ed3246a8717dd6a6102827820c259950bd77515953
crc32: BE3E52E4
md5: 1d1199a4e9824da0cda93fc5420fb050
sha1: 1700230330149601491df1deb3660962d05baca0
sha256: 7754904ddd9031c47adcf4ed3246a8717dd6a6102827820c259950bd77515953
sha512: dea26c88da2d1dbe2e122d2b455f4c18717309c95e11684545600b36983b38f9404faf6c3bb1ebefee546bb76737f8e7296442e75803d189b0704e8294aa9a5f
ssdeep: 12288:HmUCq7CR9ZAnSOhXZmQZAcy9Wp0GIeWy6MPLzyfDRtROhUO0dGzSc3F:GxfjZoSatZAcKW1F6XfMh4OSa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8E4AE22F2E05833D173263D9C1B9764983ABE103E28AD4A2BF91D4D5F7D7813979293
sha3_384: 2996d8bb27f8765ac356391c70864c148373b8ab3d1ec02acb92135dc061a6b6a550a0fad9f6d342a1996e0efb977426
ep_bytes: 558bec83c4f0b8381c4600e8403efaff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Injector.DQCE also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.10356
MicroWorld-eScanGen:Variant.Zusy.334710
FireEyeGeneric.mg.1d1199a4e9824da0
ALYacGen:Variant.Zusy.334710
CylanceUnsafe
SangforTrojan.Win32.Trickster.vv
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Trickster.311e5b67
K7GWTrojan ( 005127fa1 )
K7AntiVirusTrojan ( 005127fa1 )
BitDefenderThetaGen:NN.ZelphiF.34212.RGW@au60s6dc
VirITTrojan.Win32.TrickBot.R
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.DQCE
TrendMicro-HouseCallTROJ_GRAFTOR_GG3102FE.UVPM
Paloaltogeneric.ml
ClamAVWin.Packed.Trickbot-6333872-1
KasperskyTrojan.Win32.Trickster.vv
BitDefenderGen:Variant.Zusy.334710
NANO-AntivirusTrojan.Win32.GenKryptik.ercnuj
ViRobotTrojan.Win32.S.Agent.712704.HY
AvastWin32:Malware-gen
TencentWin32.Trojan.Trickster.Dygn
Ad-AwareGen:Variant.Zusy.334710
TACHYONTrojan/W32.DP-Trickster.712704.B
EmsisoftGen:Variant.Zusy.334710 (B)
ComodoTrojWare.Win32.TrickBot.O@7769kv
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GRAFTOR_GG3102FE.UVPM
McAfee-GW-EditionGenericR-KBH!1D1199A4E982
SophosMal/Generic-R + Troj/TrickBt-E
IkarusTrojan.Win32.Krypt
GDataGen:Variant.Zusy.334710
JiangminTrojan.Trickster.ik
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1219923
Antiy-AVLTrojan/Win32.Trickster
ArcabitTrojan.Zusy.D51B76
SUPERAntiSpywareTrojan.Agent/Gen-Norkryp
ZoneAlarmTrojan.Win32.Trickster.vv
MicrosoftTrojan:Win32/Fareit!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Trickbot.C2045094
McAfeeGenericR-KBH!1D1199A4E982
MAXmalware (ai score=84)
VBA32TScope.Trojan.Delf
MalwarebytesSpyware.LokiBot
APEXMalicious
RisingTrojan.TrickBot!1.AC7C (CLASSIC)
YandexTrojan.GenAsa!QjXqG+HLUGQ
FortinetW32/GenKryptik.APGY!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4e9824
PandaTrj/GdSda.A

How to remove Win32/Injector.DQCE?

Win32/Injector.DQCE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment