Malware

What is “Win32/Injector.DTPV”?

Malware Removal

The Win32/Injector.DTPV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DTPV virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Win32/Injector.DTPV?


File Info:

crc32: 31BDAE47
md5: a5ab0b439dbe5a12f40eda7c020b1ee3
name: A5AB0B439DBE5A12F40EDA7C020B1EE3.mlw
sha1: 60cf3cecd39d82c131c75eaeb2ed3353853419b5
sha256: ceb0152cfbe3f282e114c269fd46ba389057c8d9b984c70e10df08752b229669
sha512: 9cc8fef963cca8073b82e11ef9e22fdf0edbbdf9937441f519f673e815015b23a8fc06f3f80c2a2b50659c0d7b33b923e73880d35f6026c006873fdec33e6b85
ssdeep: 3072:2bmrL4ngyIIVodQ6NYZYAC7+YOWVPeqrA2fd6EK8:2bmInPRodfYaTaC2t2F66
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
InternalName: Sydne
FileVersion: 1.01
LegalTrademarks: SKype
ProductName: TExas Instruments Incorporated
ProductVersion: 1.01
FileDescription: HOla Networks Ltd.
OriginalFilename: Sydne.exe

Win32/Injector.DTPV also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.2092
FireEyeGeneric.mg.a5ab0b439dbe5a12
McAfeeFareit-FKB!A5AB0B439DBE
MalwarebytesSpyware.Pony
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Fareit.320cb7e9
K7GWTrojan ( 0051c1fb1 )
K7AntiVirusTrojan ( 0051c1fb1 )
CyrenW32/VBInject.MY.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.DTPV
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.PonyStealer.lm0@cWaX0NnG
MicroWorld-eScanGen:Heur.PonyStealer.lm0@cWaX0NnG
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Heur.PonyStealer.lm0@cWaX0NnG
SophosML/PE-A + Mal/FareitVB-M
BitDefenderThetaGen:NN.ZevbaF.34126.lm0@aWaX0NnG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
EmsisoftGen:Heur.PonyStealer.lm0@cWaX0NnG (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112788
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.PonyStealer.EFDE3D
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
MAXmalware (ai score=99)
PandaTrj/GdSda.A
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.PWS.Fareit!VmKe2JRCoCg
IkarusTrojan-PSW.Fareit
FortinetW32/GenKryptik.BEEC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DTPV?

Win32/Injector.DTPV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment