Malware

What is “Win32/Injector.EAOX”?

Malware Removal

The Win32/Injector.EAOX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EAOX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Indonesian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Win32/Injector.EAOX?


File Info:

crc32: 1F04BC4A
md5: bb2bec7d00986388ccd20c928f81e159
name: BB2BEC7D00986388CCD20C928F81E159.mlw
sha1: 2970b2d3d00b24e36174d760af9df562599f0c32
sha256: 891f737637e7fb268621f844c7b41ec63a98b716196761687b1ae150e3a5ed75
sha512: 75b8ac200d0bc413b467250891a38b4abe6fda16239f594c60bbb5f0c2e56c219fe17eb933a003d9193281c6ac001f02e3e10773b5ce7ef1617c84c1260d4356
ssdeep: 3072:rWPm0Gz8Zd2Vk+uryF+wWqG8z9GnSkGT2JqbIb4P8e8x08:rWPpN8kGWqG8z0nSk07k+D8y8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EAOX also known as:

BkavW32.Common.9F09F6A9
K7AntiVirusTrojan ( 0053cfdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.836
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/GandCrypt.d4f23f04
K7GWTrojan ( 0053cfdf1 )
Cybereasonmalicious.d00986
CyrenW32/Injector.ACO.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Injector.EAOX
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Dropper.Gandcrab-9752130-0
KasperskyTrojan-Ransom.Win32.GandCrypt.fio
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.GandCrypt.fiekto
ViRobotTrojan.Win32.U.GandCrab.182784
SUPERAntiSpywareTrojan.Agent/Gen-Injector
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34670.luW@amoX7yeG
TrendMicroRansom_GANDCRAB.THOIBFAH
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.bb2bec7d00986388
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.ng
AviraHEUR/AGEN.1106537
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Occamy.C
AegisLabTrojan.Win32.GandCrypt.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.Q
AhnLab-V3Win-Trojan/MalPe36.Suspicious.X2037
Acronissuspicious
McAfeeTrojan-FQPW!BB2BEC7D0098
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.THOIBFAH
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.GenAsa!Q4A7BFWy9NU
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GMSM!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Win32/Injector.EAOX?

Win32/Injector.EAOX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment