Malware

Win32/Injector.DVKV (file analysis)

Malware Removal

The Win32/Injector.DVKV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DVKV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.DVKV?


File Info:

name: A9072A52EDBD87708DA3.mlw
path: /opt/CAPEv2/storage/binaries/f06f18e2f1580434d53d869d679c552e1ef1f94548a5b3c756c9e6988811178d
crc32: F08BFBB1
md5: a9072a52edbd87708da3ffcd0b698e29
sha1: 85f69b325de1f536541e79ad00af88cbf17bc02d
sha256: f06f18e2f1580434d53d869d679c552e1ef1f94548a5b3c756c9e6988811178d
sha512: 09a6510b5b6b85eb6873df324e00fa78f23c5dd342bbfa3d54cbdc881697178d38c79a4e159b348880dbe7362ea574bc3c7167f9c05c15c10dd7d08355953533
ssdeep: 3072:zHThVeRQie1va9CXpRtnwG4yVd1x5iGBzuud6gPIPFvu9hvQrnNN/Y5LBIoo:zR1CUP3TP51rwPFrGC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18694D002B62D73D0D76086B05C7FADF46F933C7DC94A4CA2354E36AA1CBB5409BA6325
sha3_384: 5534f7aa30e8580af03c57e8386ff8de4e2da803b9058a496c1c66a0eb7b68bcedaf68f07720ae1cba084e28b9642409
ep_bytes: 680c144000e8eeffffff000000000000
timestamp: 2018-01-28 23:55:36

Version Info:

Translation: 0x0409 0x04b0
CompanyName: skype
FileDescription: fOObar2000.org
ProductName: Spicevpn.com
FileVersion: 9.04
ProductVersion: 9.04
InternalName: Stridden1
OriginalFilename: Stridden1.exe

Win32/Injector.DVKV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.zm0@cuGArili
McAfeePacked-YP!A9072A52EDBD
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Heur.PonyStealer.zm0@cuGArili
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005254051 )
AlibabaTrojan:Win32/VBKrypt.bad743df
K7GWTrojan ( 005254051 )
Cybereasonmalicious.25de1f
ArcabitTrojan.PonyStealer.E91C7D
VirITTrojan.Win32.VBZenPack_Heur
CyrenW32/Injector.LN.gen!Eldorado
SymantecPacked.Generic.520
ESET-NOD32a variant of Win32/Injector.DVKV
APEXMalicious
ClamAVWin.Malware.Fareit-6826063-0
KasperskyTrojan.Win32.VBKrypt.yytl
BitDefenderGen:Heur.PonyStealer.zm0@cuGArili
NANO-AntivirusTrojan.Win32.VBKrypt.exofku
AvastWin32:Malware-gen
EmsisoftGen:Heur.PonyStealer.zm0@cuGArili (B)
F-SecureHeuristic.HEUR/AGEN.1334642
ZillyaTrojan.VBKrypt.Win32.292804
TrendMicroTSPY_HPFAREIT.SMVB
McAfee-GW-EditionPacked-YP!A9072A52EDBD
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a9072a52edbd8770
SophosMal/FareitVB-M
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraHEUR/AGEN.1334642
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.VBKrypt
MicrosoftTrojan:Win32/Fareit!ml
ZoneAlarmTrojan.Win32.VBKrypt.yytl
GDataGen:Heur.PonyStealer.zm0@cuGArili
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
BitDefenderThetaGen:NN.ZevbaF.36722.zm0@auGArili
ALYacGen:Heur.PonyStealer.zm0@cuGArili
VBA32BScope.Trojan.VBKrypt
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_HPFAREIT.SMVB
TencentMalware.Win32.Gencirc.1154eb0b
YandexTrojan.Igent.b0CR3s.2
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKryptik.DZLN!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.DVKV?

Win32/Injector.DVKV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment