Malware

Should I remove “Win32/Injector.DWXT”?

Malware Removal

The Win32/Injector.DWXT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DWXT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.DWXT?


File Info:

crc32: 09012478
md5: ec24d0f6f9dafb6f4b4a262370cdb316
name: EC24D0F6F9DAFB6F4B4A262370CDB316.mlw
sha1: 85a0a5634809afaeb5bdcd389d12b42440b06cb5
sha256: 238afeb4667b198eb0346f3c74d3c44790f533603e617d43ce79627d91d6c81c
sha512: 814d3fc78e234b1929a2b82e8e7119de1597fb73e594dd6e7d1469ba643ebba80dfb0c1efea1362b579c7e85db71dde84b67eb9bf24c87a0c83995e54acb323b
ssdeep: 3072:wByhIRMTwAORLc8UmoXklGhlZGoQQ+Xqwt/w2XQYHlLTa9ecz6fdnFU3RLeljhk:UyTnEhvshlZrQQ+Xqwt/wgRmrzXWaAI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: HEwleTT PAckaRD Si:
InternalName: Bractless
FileVersion: 6.05
CompanyName: gA mA SOFT
LegalTrademarks: DRopBOx= INC?
Comments: EP SOn
ProductName: FILseCLaB COrpORAtion
ProductVersion: 6.05
FileDescription: Evg TEchNOLOgies
OriginalFilename: Bractless.exe

Win32/Injector.DWXT also known as:

K7AntiVirusTrojan ( 0052c10c1 )
LionicTrojan.Win32.VBKrypt.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.Bm0@fLWALHfi
CylanceUnsafe
SangforTrojan.Win32.VBKrypt.zgqs
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0052c10c1 )
Cybereasonmalicious.6f9daf
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.DWXT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Noon-6915599-0
KasperskyTrojan.Win32.VBKrypt.zgqs
BitDefenderGen:Trojan.Heur.Bm0@fLWALHfi
NANO-AntivirusTrojan.Win32.VBKrypt.ezkwsj
MicroWorld-eScanGen:Trojan.Heur.Bm0@fLWALHfi
TencentMalware.Win32.Gencirc.114cdfe1
Ad-AwareGen:Trojan.Heur.Bm0@fLWALHfi
SophosMal/Generic-R + Mal/VB-F
ComodoMalware@#2b2obfvh17lel
BitDefenderThetaAI:Packer.53C5B9341C
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPFAREIT.SM4
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gc
FireEyeGeneric.mg.ec24d0f6f9dafb6f
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.VB.haoko
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.2533A32
MicrosoftVirTool:Win32/VBInject.AHU!bit
ArcabitTrojan.Heur.E073E7
GDataWin32.Trojan.Injector.NA
AhnLab-V3Trojan/Win32.Fareit.R223536
McAfeeFareit-FLA!EC24D0F6F9DA
MAXmalware (ai score=99)
VBA32Trojan.VB.gen
MalwarebytesBackdoor.PasswordStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_HPFAREIT.SM4
RisingTrojan.Injector!1.B459 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.12260899.susgen
FortinetW32/Injector.EASF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DWXT?

Win32/Injector.DWXT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment