Malware

How to remove “Win32/Injector.DXKV”?

Malware Removal

The Win32/Injector.DXKV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DXKV virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.DXKV?


File Info:

crc32: 68802DBB
md5: a31024d273b264971da3b851fdafb0a3
name: A31024D273B264971DA3B851FDAFB0A3.mlw
sha1: 785afaf89547a5a90b15590e3920076232f839d6
sha256: 8a2ad86497e4bef7911cc25faa12d80e992b1b91e4834f7907608511610a6800
sha512: 02f2c43013df2268f9f457d8945625396a2dd7e724d73aa482893291d17a0718e29177d14e00386de4d9f1efe131ddd6e4cd6be20d8dcf1e3f9775d0d55c9341
ssdeep: 12288:dpzKXQP1IYUdUELzfO436OHgmRqLuriZfvQNZ/u:z+APWYUdfLDOygmRqLurE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: finaREA R,a, SWITZERLAND
InternalName: Colius
FileVersion: 1.00
CompanyName: KOLe netWORKS sTD,
Comments: Bim
ProductName: stelLAR INFORMATION systEMS CTd
ProductVersion: 1.00
OriginalFilename: Colius.exe

Win32/Injector.DXKV also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052e1981 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.15120
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Sm0@dGfDLqai
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.41018
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0052e1981 )
Cybereasonmalicious.273b26
CyrenW32/Trojan.BHU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DXKV
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.HawkEye-7122916-2
KasperskyTrojan-Ransom.Win32.Blocker.kysc
BitDefenderGen:Heur.PonyStealer.Sm0@dGfDLqai
NANO-AntivirusTrojan.Win32.Blocker.fanbkq
MicroWorld-eScanGen:Heur.PonyStealer.Sm0@dGfDLqai
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Heur.PonyStealer.Sm0@dGfDLqai
SophosMal/Generic-R + Mal/FareitVB-L
ComodoMalware@#2xlrh16474ped
BitDefenderThetaGen:NN.ZevbaF.34670.Sm0@aGfDLqai
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPFAREIT.SM4
McAfee-GW-EditionBehavesLike.Win32.Fareit.bc
FireEyeGeneric.mg.a31024d273b26497
EmsisoftGen:Heur.PonyStealer.Sm0@dGfDLqai (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1121803
eGambitUnsafe.AI_Score_100%
MicrosoftVirTool:Win32/VBInject.AHU!bit
ArcabitTrojan.PonyStealer.E896C5
AegisLabTrojan.Win32.Blocker.4!c
GDataGen:Heur.PonyStealer.Sm0@dGfDLqai
AhnLab-V3Win-Trojan/VBKrypt.RP.X1777
McAfeeGenericRXEZ-RP!A31024D273B2
MAXmalware (ai score=99)
VBA32TrojanRansom.Blocker
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_HPFAREIT.SM4
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!1jIFVlA/gLw
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BWYL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASQwA

How to remove Win32/Injector.DXKV?

Win32/Injector.DXKV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment