Malware

Win32/Injector.DWQI removal instruction

Malware Removal

The Win32/Injector.DWQI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DWQI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

onlygoodman.com
ww1.onlygoodman.com

How to determine Win32/Injector.DWQI?


File Info:

crc32: E00207E3
md5: 9e561c6fef2ddd4a6472f53e60959b15
name: 9E561C6FEF2DDD4A6472F53E60959B15.mlw
sha1: 42e8f537db8fb86458f46e5c9f874ebff37de85f
sha256: d1b9d1321f517d78bc0d1d03c5ed3c20a1ccb85bf755bb3a9a903d43fb6ce5f7
sha512: f6e7cfb3fe597ae5e96bc64232fe0361d5a60064b55c733375f8e39d53b3e80bf9cace2941f4c3a57e953251feb3a488939fd647eec5a9aeb662884fd3f16914
ssdeep: 6144:qMrPeku4wGU+iLUuMCFYHJ7vl7y+LE/f6/m2zGG5:5mNPGUXUuvF2r1y+LEH6/lzGG5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Anaerobion
FileVersion: 5.02
CompanyName: LEXUS
ProductName: http:\WWW.light=alloY.RU
ProductVersion: 5.02
OriginalFilename: Anaerobion.exe

Win32/Injector.DWQI also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052aaa51 )
LionicTrojan.Win32.Fareit.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23366
CynetMalicious (score: 99)
ALYacGen:Heur.PonyStealer.Bm0@cK3R4@mi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0052aaa51 )
Cybereasonmalicious.fef2dd
CyrenW32/Kryptik.CW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DWQI
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-PSW.Win32.Fareit.dump
BitDefenderGen:Heur.PonyStealer.Bm0@cK3R4@mi
NANO-AntivirusTrojan.Win32.Fareit.ezhblx
MicroWorld-eScanGen:Heur.PonyStealer.Bm0@cK3R4@mi
TencentWin32.Trojan-qqpass.Qqrob.Hvsw
Ad-AwareGen:Heur.PonyStealer.Bm0@cK3R4@mi
SophosML/PE-A + Mal/FareitVB-L
ComodoMalware@#12n6l8fkvfvb6
BitDefenderThetaGen:NN.ZevbaF.34142.Bm0@aK3R4@mi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPFAREIT.SMVB
McAfee-GW-EditionBehavesLike.Win32.Packed.gt
FireEyeGeneric.mg.9e561c6fef2ddd4a
EmsisoftGen:Heur.PonyStealer.Bm0@cK3R4@mi (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.VB.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.25216AC
MicrosoftVirTool:Win32/VBInject.AID!bit
ArcabitTrojan.PonyStealer.E25C95
GDataGen:Heur.PonyStealer.Bm0@cK3R4@mi
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
McAfeeFareit-FLA!9E561C6FEF2D
MAXmalware (ai score=98)
VBA32BScope.Trojan.MSIL.Disfa
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_HPFAREIT.SMVB
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.PWS.Fareit!Xu1I6m1/LSA
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DWPX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DWQI?

Win32/Injector.DWQI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment