Malware

About “Win32/Injector.DRUX” infection

Malware Removal

The Win32/Injector.DRUX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DRUX virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.DRUX?


File Info:

crc32: E5409EBD
md5: b88da76d6bb5546bd3227efebf9d9ea3
name: B88DA76D6BB5546BD3227EFEBF9D9EA3.mlw
sha1: 33c88ce1ee7dd4bbb287585f300f578decad8d71
sha256: de022b5aa15bafd67f24029cea5b3a06492fbebcedf0f6a4b2cae6a56543a2d5
sha512: ba9c520603eeeb64c4075b782aa2dc965b2f43f8dadb7022d79d366cb5964489f68e680de6532d03c6eb52681cfcd3696bd3dc35af7b5aea4c940c341e429fea
ssdeep: 12288:2a/ek1n0jdIstJkjEmORP1WPqrTPBDaHXEKV:21TTaj0Rd9LI0KV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Khums
FileVersion: 1.00.0006
ProductName: http://tika.fs
ProductVersion: 1.00.0006
FileDescription: Beus
OriginalFilename: Khums.exe

Win32/Injector.DRUX also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.Vm0@ea3GFkoi
ALYacGen:Heur.PonyStealer.Vm0@ea3GFkoi
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005166c01 )
BitDefenderGen:Heur.PonyStealer.Vm0@ea3GFkoi
K7GWTrojan ( 005166c01 )
Cybereasonmalicious.d6bb55
BitDefenderThetaGen:NN.ZevbaF.34804.Vm0@aa3GFkoi
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.VBKrypt.xytm
AlibabaTrojan:Win32/VBKrypt.09652dce
NANO-AntivirusTrojan.Win32.GenericKD.esomfq
AegisLabTrojan.Win32.Generic.4!c
AvastWin32:Malware-gen
RisingBackdoor.Noancooe!8.176 (CLOUD)
Ad-AwareGen:Heur.PonyStealer.Vm0@ea3GFkoi
EmsisoftGen:Heur.PonyStealer.Vm0@ea3GFkoi (B)
ComodoMalware@#giu91016now
F-SecureHeuristic.HEUR/AGEN.1119922
ZillyaTrojan.GenericKD.Win32.73963
TrendMicroBKDR_TOFSEE.SMF
McAfee-GW-EditionPacked-QD!B88DA76D6BB5
FireEyeGeneric.mg.b88da76d6bb5546b
SophosML/PE-A + Mal/FareitVB-M
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1119922
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftBackdoor:MSIL/Noancooe.C
ArcabitTrojan.PonyStealer.EC24DE
ZoneAlarmTrojan.Win32.VBKrypt.xytm
GDataGen:Heur.PonyStealer.Vm0@ea3GFkoi
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R208377
McAfeePacked-QD!B88DA76D6BB5
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32a variant of Win32/Injector.DRUX
TrendMicro-HouseCallBKDR_TOFSEE.SMF
TencentMalware.Win32.Gencirc.114975dd
YandexTrojan.VBKrypt!7/3NUA3zYsE
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.DPDX!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.362

How to remove Win32/Injector.DRUX?

Win32/Injector.DRUX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment