Malware

Win32/Injector.DXTP removal

Malware Removal

The Win32/Injector.DXTP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DXTP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.DXTP?


File Info:

crc32: 341DB039
md5: 3ce66caa331cbde38b08ac28665057ed
name: 3CE66CAA331CBDE38B08AC28665057ED.mlw
sha1: 65113ab42af92d2888005f77a38f319ae7957583
sha256: d3e8a314209b568a8161c36aba3c799860ec55c867a4d9ded2183657d0e37eed
sha512: 40b636c384e7ee469954f160fb2e42daa6fd17ecffc5b694a85c96f4fd8d5b188a1d1e2c715a2f537ebf648c9317e73628bb5dffcb7b4c0669e0b91364dc7b8d
ssdeep: 12288:R4TZJHtqPRx+9Bvw6VjWVmzafcWf/rKpHGAcKEZUiX:RmJHjDpiNnGpHGFPZUi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: GJSe 'computiNG FORceo'
InternalName: Bathypelagic
FileVersion: 1.07
LegalTrademarks: ePSON
Comments: HEA Ve TOop soft war
ProductName: tie kOSSA
ProductVersion: 1.07
OriginalFilename: Bathypelagic.exe

Win32/Injector.DXTP also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052f9e21 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.On0@dWYDJdpi
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.299213
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0052f9e21 )
Cybereasonmalicious.a331cb
SymantecPacked.Generic.531
ESET-NOD32a variant of Win32/Injector.DXTP
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Downloader.LokiBot-9165134-0
KasperskyTrojan.Win32.VBKrypt.zkjt
BitDefenderGen:Heur.PonyStealer.On0@dWYDJdpi
NANO-AntivirusTrojan.Win32.VBKrypt.fbeges
MicroWorld-eScanGen:Heur.PonyStealer.On0@dWYDJdpi
Ad-AwareGen:Heur.PonyStealer.On0@dWYDJdpi
SophosML/PE-A + Mal/FareitVB-AB
BitDefenderThetaGen:NN.ZevbaF.34796.On0@aWYDJdpi
TrendMicroTSPY_HPLOKI.SMVBMP0
FireEyeGeneric.mg.3ce66caa331cbde3
EmsisoftGen:Heur.PonyStealer.On0@dWYDJdpi (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.VBKrypt.eqjn
AviraHEUR/AGEN.1117871
Antiy-AVLTrojan/Generic.ASMalwS.2608788
MicrosoftVirTool:Win32/VBInject.AHV!bit
GDataGen:Heur.PonyStealer.On0@dWYDJdpi
TACHYONTrojan/W32.Inject.1703936
AhnLab-V3Win-Trojan/VBKrypt.RP12.X2026
McAfeeGenericRXPG-ZY!3CE66CAA331C
MAXmalware (ai score=84)
VBA32Trojan.VBKrypt
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_HPLOKI.SMVBMP0
RisingTrojan.Injector!1.B459 (CLASSIC)
FortinetW32/GenKryptik.CBCD!tr
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM03.0.AB77.Malware.Gen

How to remove Win32/Injector.DXTP?

Win32/Injector.DXTP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment