Malware

How to remove “Win32/Injector.DYRS”?

Malware Removal

The Win32/Injector.DYRS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DYRS virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Injector.DYRS?


File Info:

name: F9DAFE1DCACF03B937ED.mlw
path: /opt/CAPEv2/storage/binaries/29904ef4944695d409a0a3e6d6fa4fa86dd56ccf4c4b1922584b13ae1bf78bc9
crc32: 681ECD7A
md5: f9dafe1dcacf03b937ed0973d508fa3c
sha1: 1916b559f3af54a40506ec84c0bdc55b4293a35a
sha256: 29904ef4944695d409a0a3e6d6fa4fa86dd56ccf4c4b1922584b13ae1bf78bc9
sha512: 9ebd7293532da27093c4bf2fd2a7656f3851249b577cb91f9e2f14dec355cf6863cb2ec9f84b9d99d253ae17232d4fe45ec5fb780577a3a98bbabcd374876673
ssdeep: 12288:FtPGV4W3nZYCI70zWriNPX6TRRWHyPr417kFynPob8aX:Fp29ZYCI7CW6P6R62r417kFynAb8a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3B47E73F2E14977C177363D9C6B5768AC2ABF112A2834862FE81C4C4F3979139291A7
sha3_384: b53fcf2971400d49b180bfc7823a13fbdf771bbc4cef5d330f40107588a4c2e7fb641e9c76ba10b793cd2390d08d2b1d
ep_bytes: 558bec83c4f0b8c4394700e8c826f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Injector.DYRS also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47708660
FireEyeTrojan.GenericKD.47708660
McAfeeGenericRXAA-AA!F9DAFE1DCACF
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan ( 0055fde71 )
AlibabaTrojanBanker:Win32/ClipBanker.5f211c09
K7GWTrojan ( 0055fde71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DYRS
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.ClipBanker.gen
BitDefenderTrojan.GenericKD.47708660
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.47708660
TrendMicroTROJ_GEN.R053C0WLP21
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftTrojan.GenericKD.47708660 (B)
GDataWin32.Trojan.Agent.K1BEJ3
JiangminTrojan/Llac.xyw
AviraHEUR/AGEN.1145869
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.DealPly.C3472901
BitDefenderThetaGen:NN.ZelphiF.34114.GGW@aWPbwGbc
ALYacTrojan.GenericKD.47708660
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R053C0WLP21
YandexTrojan.GenAsa!AtJJ4wzdXsM
FortinetW32/DYRS!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Win32/Injector.DYRS?

Win32/Injector.DYRS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment