Malware

Win32/Injector.DTZD removal instruction

Malware Removal

The Win32/Injector.DTZD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DTZD virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The executable is likely packed with VMProtect
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

dcyvknqcsvgn.work
awujkqrlyamvipip.click
hemjlfidtkvloito.work
mosxuotpgjujkcq.click
fegfihmbivmusit.pl
bqhngkoxq.info

How to determine Win32/Injector.DTZD?


File Info:

crc32: 0EC7BEA1
md5: aa07d4d1b10bfacca682d3c983a9da6f
name: AA07D4D1B10BFACCA682D3C983A9DA6F.mlw
sha1: 9cc82de15cc1babcc068026be456eb87cdb980f9
sha256: 3db5e189af7c90a66239c9a12fe2a3a055606e08041d94f419467befbcfd69d4
sha512: a8cbf3ba4fa21793479c42665e6404b1ce4263ac462a55b85af8601ff9ce085c064e2cc22cb0f457d99da1d7b2576a547798abedb1ab28d1dbbd7ccf09e3c53f
ssdeep: 1536:JHJQAoLjmn2X1DED3Qq51J5VCIyAmg6PzZ1bj2lQ5L+e1K:DQAoPmqq5n54Iy3jvj2lmD1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.DTZD also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0051cdbc1 )
LionicTrojan.Win32.Generic.lGmj
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
CAT-QuickHealRansomware.Teslacrypt.WR4
ALYacTrojan.Brsecmon.1
CylanceUnsafe
SangforTrojan.Win32.Satan.1
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0051cdbc1 )
Cybereasonmalicious.1b10bf
CyrenW32/Locky.AD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DTZD
APEXMalicious
AvastWin32:Dorder-AC [Trj]
KasperskyTrojan-Ransom.Win32.Locky.acju
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Locky.evdded
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Locky.Llgx
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-S
ComodoMalware@#i2zo6zp6hwbi
BitDefenderThetaAI:Packer.EE153E3B1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.aa07d4d1b10bfacc
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1101942
Antiy-AVLTrojan/Generic.ASMalwS.22B907A
MicrosoftRansom:Win32/Locky.A
GDataTrojan.Brsecmon.1
Acronissuspicious
McAfeeGenericRXAA-AA!AA07D4D1B10B
MAXmalware (ai score=62)
VBA32BScope.TrojanRansom.Centrum
PandaTrj/GdSda.A
RisingRansom.Satan!1.AEB7 (CLASSIC)
YandexTrojan.GenAsa!f+OZOmj2CCM
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.FCHC!tr
AVGWin32:Dorder-AC [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Locky.HxQBEpsA

How to remove Win32/Injector.DTZD?

Win32/Injector.DTZD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment