Malware

Win32/Injector.DVEQ information

Malware Removal

The Win32/Injector.DVEQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DVEQ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.legalcollectors.cf

How to determine Win32/Injector.DVEQ?


File Info:

crc32: 4DA4FB79
md5: 153f286dd4809aed103109c9eaeb5a47
name: 153F286DD4809AED103109C9EAEB5A47.mlw
sha1: 659f7c67bec211a1645b9fead848a2c68ec2e3ff
sha256: dd4553a93d6f49eef38882cad2f98f3bc3cb1da0003010d5d9ba876c1aac8ea4
sha512: 5a847eb0de529e8081e458c4fddbe5331d9871e12f97b9ae84300e54ecfeb12e0161ef14ec64b644e8fd1f6c52beab459615edbbc77832dde4407024aee71aa8
ssdeep: 3072:5V03cP1268E2/b15emuaDOCxAXYNDvIF6yUY5uYTEEHenYTPmgqLyKSTPm:wcP126n255mamXOM6yUmTHeNd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: KaSSpaSS
InternalName: Warnel1
FileVersion: 1.04
CompanyName: aVure CaE
LegalTrademarks: iMSiSOFT aCvA
ProductName: HaRaSoft
ProductVersion: 1.04
FileDescription: FaTONsoFT aIb.
OriginalFilename: Warnel1.exe

Win32/Injector.DVEQ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005245101 )
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Heur.PonyStealer.Fm0@fOK43Rii
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/VBKrypt.c73fa8f5
K7GWTrojan ( 005245101 )
Cybereasonmalicious.dd4809
CyrenW32/Fareit.DJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DVEQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.PonyStealer.Fm0@fOK43Rii
NANO-AntivirusTrojan.Win32.VBKrypt.exiqgn
MicroWorld-eScanGen:Heur.PonyStealer.Fm0@fOK43Rii
TencentWin32.Trojan.Vbkrypt.Dvzz
Ad-AwareGen:Heur.PonyStealer.Fm0@fOK43Rii
SophosMal/Generic-R + Mal/FareitVB-M
ComodoMalware@#1gdsxrayw8sj1
BitDefenderThetaGen:NN.ZevbaF.34170.Fm0@aOK43Rii
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPLOKI.SMVB
McAfee-GW-EditionBehavesLike.Win32.Fareit.hz
FireEyeGeneric.mg.153f286dd4809aed
EmsisoftGen:Heur.PonyStealer.Fm0@fOK43Rii (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VBKrypt.chgo
WebrootW32.Gen.BT
AviraHEUR/AGEN.1109917
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2416A18
MicrosoftVirTool:Win32/VBInject.PD!bit
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.PonyStealer.Fm0@fOK43Rii
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
McAfeePacked-WM!153F286DD480
VBA32BScope.Trojan.Wacatac
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_HPLOKI.SMVB
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.VBKrypt!jF+dPLa3Pik
IkarusTrojan.Win32.Injector
FortinetW32/VBKryptik.DZLN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DVEQ?

Win32/Injector.DVEQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment