Malware

How to remove “Win32/Injector.DVTX”?

Malware Removal

The Win32/Injector.DVTX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DVTX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.DVTX?


File Info:

crc32: C947C539
md5: 1bd3af0ad6f5f9a62c7985a10af1b516
name: 1BD3AF0AD6F5F9A62C7985A10AF1B516.mlw
sha1: 19866acd6a3e3022ee09ecc6a89e56d42fa8bec3
sha256: 0073ac21688a76d58b1da9bdf08989053248d9f941a69c70655d021b68459d08
sha512: f10334314ea447eca596e30a682aaac13f3a87d75c386c7d34be52d3a78549e2cd8b783b4cc64ccdb4289322aac1b6aba1cce93e2457958bb50005e52026473a
ssdeep: 3072:x+qztadKGIYs9pk+nkQmADiuW4iaSXq2O4Fw5YfXsbK4Bw6AbgNMbu6l8moDAM:x+4CTIYkpxXxW4iFXCRK4BwYc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Arlyne7
FileVersion: 2.08
CompanyName: lnTiL
ProductName: EAin EiDIa ELe
ProductVersion: 2.08
FileDescription: ERICLa EARPoraTOO
OriginalFilename: Arlyne7.exe

Win32/Injector.DVTX also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00526e051 )
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Dm0@cqmwTKbi
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.301415
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/VBKrypt.90299984
K7GWTrojan ( 00526e051 )
Cybereasonmalicious.ad6f5f
CyrenW32/Kryptik.ATC.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.DVTX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Ponystealer-7745271-0
KasperskyTrojan.Win32.VBKrypt.zbcb
BitDefenderGen:Heur.PonyStealer.Dm0@cqmwTKbi
NANO-AntivirusTrojan.Win32.VBKrypt.eyatwi
MicroWorld-eScanGen:Heur.PonyStealer.Dm0@cqmwTKbi
TencentMalware.Win32.Gencirc.114cddd2
Ad-AwareGen:Heur.PonyStealer.Dm0@cqmwTKbi
SophosML/PE-A + Mal/FareitVB-M
BitDefenderThetaGen:NN.ZevbaF.34142.Dm0@aqmwTKbi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPFAREIT.SMVB
McAfee-GW-EditionBehavesLike.Win32.Downloader.gt
FireEyeGeneric.mg.1bd3af0ad6f5f9a6
EmsisoftTrojan.Injector (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VBKrypt.dnco
AviraHEUR/AGEN.1112797
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.247148F
MicrosoftTrojan:Win32/Fareit!ml
GDataWin32.Trojan-Spy.VBInject.H
TACHYONTrojan/W32.VB-VBKrypt.483328.Y
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
Acronissuspicious
McAfeePacked-YP!1BD3AF0AD6F5
MAXmalware (ai score=100)
VBA32Trojan.VBKrypt
MalwarebytesSpyware.LokiBot
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_HPFAREIT.SMVB
YandexTrojan.GenAsa!x6jjtqSBSvc
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CFIF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DVTX?

Win32/Injector.DVTX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment