Malware

About “Win32/Injector.DZKS” infection

Malware Removal

The Win32/Injector.DZKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DZKS virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine Win32/Injector.DZKS?


File Info:

crc32: 02B73815
md5: eea88e8a765cf0175d648c82797ec822
name: EEA88E8A765CF0175D648C82797EC822.mlw
sha1: 08a27883da3a1ef0d674c6b745954a8698ef47c8
sha256: 7f37464f97d7fc0bda7d58f0fc8cd95e79eec102a2693e86e292904bafcf1d60
sha512: 4e74379c49d75986538246afaa8eceac9074bc0377a26a8a0645ca98be269db41501f895f4c4d086510cc97be5ecdc52584d64208cd4ef607450058f427a11ca
ssdeep: 12288:mg0hsJsdYJa+JUuHhS4IoE6oylW8TChjUnsnJi5BZRL8hU+JVJPvIh+lovT62g:mphwQZ0HhvL8hU+JVJPvIh+sT62g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: sourceFIRE, CNc.
InternalName: Filicin
FileVersion: 7.07
CompanyName: KAMstuDIO trOUp
LegalTrademarks: thundERBIRD
Comments: Xe
ProductName: audacity team
ProductVersion: 7.07
FileDescription: caNOn
OriginalFilename: Filicin.exe

Win32/Injector.DZKS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053843a1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24300
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Im0@dyCu1voi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.41743a1b
K7GWTrojan ( 0053843a1 )
Cybereasonmalicious.a765cf
CyrenW32/Fareit.FW.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.DZKS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Fareit-6626679-0
KasperskyTrojan-Ransom.Win32.Blocker.lcmc
BitDefenderGen:Heur.PonyStealer.Im0@dyCu1voi
NANO-AntivirusTrojan.Win32.Blocker.fgvicb
MicroWorld-eScanGen:Heur.PonyStealer.Im0@dyCu1voi
TencentMalware.Win32.Gencirc.114d341e
Ad-AwareGen:Heur.PonyStealer.Im0@dyCu1voi
SophosML/PE-A + Mal/FareitVB-V
BitDefenderThetaGen:NN.ZevbaF.34628.Im0@ayCu1voi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.hh
FireEyeGeneric.mg.eea88e8a765cf017
EmsisoftTrojan.Injector (A)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1121308
eGambitUnsafe.AI_Score_97%
MicrosoftVirTool:Win32/VBInject.AGP!bit
ArcabitTrojan.PonyStealer.ED1DC0C
GDataGen:Heur.PonyStealer.Im0@dyCu1voi
AhnLab-V3Trojan/Win32.Injector.R232123
McAfeeGenericRXGE-WW!EEA88E8A765C
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuerboos
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!A0NTqaVepkg
IkarusTrojan.VB.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKryptik.DZKH!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.Ransom.c24

How to remove Win32/Injector.DZKS?

Win32/Injector.DZKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment