Malware

Win32/Injector.DSBB (file analysis)

Malware Removal

The Win32/Injector.DSBB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DSBB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.DSBB?


File Info:

crc32: E0362866
md5: fe42ee47bfb165cf41fe3e9bbec9b8d1
name: FE42EE47BFB165CF41FE3E9BBEC9B8D1.mlw
sha1: 4f31a239bc4cb4b9d1d4a9ab0ac65b19e5c915f3
sha256: dd83b9b1c2d24dac4436b761ea8c1b050011c30850973256ab7319cb07244a73
sha512: 59068431e3b1f5dbf9846413717db01fa970284cb9c814188fa3ca01dd8f4e0188f5d2aac95787e20eb2770fe5e5f2ee66141b2684591616b8a78bcc90cad23a
ssdeep: 3072:73gjy1pkotUdLyFlQu9Xt6Xfpb8VsrWnkv96N1rbQZKW0VENERHt:Uy1CoKdyzXt6XfppT9CrEZK9N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Katik
InternalName: Erfar
FileVersion: 4.07.0009
CompanyName: logitECH
LegalTrademarks: Wordman3
ProductName: Bluebirds4
ProductVersion: 4.07.0009
FileDescription: Volemitol
OriginalFilename: Erfar.exe

Win32/Injector.DSBB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.lm0@dOdBtyoi
FireEyeGeneric.mg.fe42ee47bfb165cf
McAfeeFareit-FJO!FE42EE47BFB1
MalwarebytesTrojan.MalPack.VB
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.naKocTb.4!c
SangforMalware
K7AntiVirusTrojan ( 005182f71 )
BitDefenderGen:Heur.PonyStealer.lm0@dOdBtyoi
K7GWTrojan ( 005182f71 )
Cybereasonmalicious.7bfb16
CyrenW32/Fareit.BV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyBackdoor.Win32.Androm.ogni
NANO-AntivirusTrojan.Win32.Nockat.etmimz
RisingTrojan.Injector!1.B459 (CLASSIC)
Ad-AwareGen:Heur.PonyStealer.lm0@dOdBtyoi
EmsisoftGen:Heur.PonyStealer.lm0@dOdBtyoi (B)
ComodoMalware@#2sw35llg684me
F-SecureHeuristic.HEUR/AGEN.1128730
DrWebTrojan.PWS.Stealer.18836
TrendMicroTSPY_HPFAREIT.SM2
McAfee-GW-EditionFareit-FJO!FE42EE47BFB1
SophosMal/Generic-S + Mal/FareitVB-M
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128730
Antiy-AVLTrojan/Win32.Nockat
MicrosoftVirTool:Win32/VBInject.ACV!bit
ArcabitTrojan.PonyStealer.E9D8BF
ZoneAlarmBackdoor.Win32.Androm.ogni
GDataGen:Heur.PonyStealer.lm0@dOdBtyoi
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fareit.R211409
VBA32BScope.TrojanPSW.Fareit
ALYacGen:Heur.PonyStealer.lm0@dOdBtyoi
MAXmalware (ai score=99)
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DSBB
TrendMicro-HouseCallTSPY_HPFAREIT.SM2
TencentWin32.Trojan.Nockat.Efao
YandexBackdoor.Androm!aIXUbXmtmvg
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.EJMZ!tr
BitDefenderThetaGen:NN.ZevbaF.34804.lm0@aOdBtyoi
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Backdoor.5c5

How to remove Win32/Injector.DSBB?

Win32/Injector.DSBB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment