Malware

Elon.7 removal guide

Malware Removal

The Elon.7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Elon.7 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Elon.7?


File Info:

crc32: 937F5258
md5: 2055bbde7b5a1afd6ea79974d1435a98
name: upload_file
sha1: e249c4f1d0910cb4660a3d41593692a02796472f
sha256: e51abdb2023b560244802f7d9687944dc0dff3042c28d7bc7a2b517df6e24942
sha512: f21f963ea6f3c394f61780825a0971f432450a7ca94353db0ba5915a0e190f0d65025c40756597b0170a3c23fb160e27011ce4a098afe2a518efc47a06874d55
ssdeep: 24576:AQkBF2DuFBsfrCbHdtvIwTGp+olFTPPxQoZeKVbygpgPh3aFMI9R2uacQs:AQIBsfrCHdtvdTCTO2pdygpiAJads
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: zmkj.ufe
ProductionVersus: 1.0.6.22
Copyrights: Copyrighd (C) 2020, hjdk
FileV: 1.0.3
TranslationUsi: 0x0872 0x08f0

Elon.7 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.63498
MicroWorld-eScanGen:Variant.Elon.7
FireEyeGeneric.mg.2055bbde7b5a1afd
ALYacGen:Variant.Elon.7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusTrojan ( 004befdb1 )
BitDefenderGen:Variant.Elon.7
K7GWTrojan ( 004befdb1 )
Cybereasonmalicious.1d0910
BitDefenderThetaGen:NN.ZexaF.34144.kH0@ai0ZFzhG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
APEXMalicious
KasperskyTrojan-Ransom.Win32.Rack.jak
AlibabaPacked:Win32/EnigmaProtector.caeff9b6
RisingPUF.Pack-Enigma!1.BA33 (CLOUD)
Ad-AwareGen:Variant.Elon.7
EmsisoftGen:Variant.Elon.7 (B)
F-SecureHeuristic.HEUR/AGEN.1128093
Invinceaheuristic
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
AviraHEUR/AGEN.1128093
MAXmalware (ai score=99)
MicrosoftTrojan:Win32/Glupteba.GD!MTB
ArcabitTrojan.Elon.7
ZoneAlarmTrojan-Ransom.Win32.Rack.jak
GDataGen:Variant.Elon.7
CynetMalicious (score: 100)
McAfeeArtemis!2055BBDE7B5A
VBA32Trojan.Zpevdo
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002H01GU20
eGambitUnsafe.AI_Score_54%
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM18.1.E68F.Malware.Gen

How to remove Elon.7?

Elon.7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment