Malware

Win32/Injector.EAHK removal guide

Malware Removal

The Win32/Injector.EAHK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EAHK virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.Rq0WNp1b3x.com
zipansion.com
aporasal.net

How to determine Win32/Injector.EAHK?


File Info:

crc32: 1208B465
md5: 999e2b9d4135bba8bac2b358d0d3d760
name: 999E2B9D4135BBA8BAC2B358D0D3D760.mlw
sha1: c67d6422609b8dd877af711de639b52f1aa54882
sha256: aa8774a8e8656a6b0bd35e0204f1232975a00a5be61ecf161a925ac1eed1bf56
sha512: f6ec26d44f9268c69644e8c9e44b6c2a87a0a34322535aac1457425d3022166a198903f9039f1bd0c4f2793672a3bb2917c965bde5f0334afa8f8630a215191a
ssdeep: 6144:586BZOcxFMYXlm/GeThmoFAEmNMjYtUI+CkctwRlO:CeCYXUeeTh57fj6egx
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Injector.EAHK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.TP.omW@b8s4!jc
FireEyeGeneric.mg.999e2b9d4135bba8
Qihoo-360HEUR/QVM19.1.061F.Malware.Gen
McAfeeGenericRXAA-AA!999E2B9D4135
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Trojan.Heur.TP.omW@b8s4!jc
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.d4135b
BitDefenderThetaAI:Packer.6BC746D41E
CyrenW32/S-fcf8f445!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EAHK
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Generic@ML.100 (RDML:jaZF/wcI8Ri3QwigmIChNA)
Ad-AwareGen:Trojan.Heur.TP.omW@b8s4!jc
EmsisoftGen:Trojan.Heur.TP.omW@b8s4!jc (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.ULPM.Gen
TrendMicroPAK_Xed-10
SophosML/PE-A + Mal/TibsPak
AviraTR/Crypt.ULPM.Gen
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Heur.TP.EC3EB3
AhnLab-V3Trojan/Win32.Agent.R243892
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.TP.omW@b8s4!jc
CynetMalicious (score: 100)
VBA32BScope.Trojan.Wacatac
ALYacGen:Trojan.Heur.TP.omW@b8s4!jc
MAXmalware (ai score=83)
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-10
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FFP!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Injector.EAHK?

Win32/Injector.EAHK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment