Malware

Win32/Injector.EBKN information

Malware Removal

The Win32/Injector.EBKN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EBKN virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EBKN?


File Info:

crc32: 0981C9B2
md5: 22993312ffe3ad385c1177551aca495e
name: 22993312FFE3AD385C1177551ACA495E.mlw
sha1: d17798ee4bea952be3a221736e3f9d2c22727704
sha256: c5b2b47e479d75976ccc3a6a797b350e8598d175417bed032f105c238564226a
sha512: ec2da87b088ab2c9bb5da4f90cabb6bdc824230cd764e9aa29233e6ccd096055b0b7ff789ecfa968ecc1a94e94edaf753b1bbe47dd1ef2c6e45f5f16d0cb376b
ssdeep: 6144:DuVuJZ6sH8IT4h9vE6DzIOEXA760xn08HdsrkMlTWVV9NaqOpaeS6zM2ABXUyBR:DuVuJ7cImvExTCRqbZezexD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: WINTERANACEAE
FileVersion: 5.09
CompanyName: Twitterboned9
Comments: PEPSINOGENIC1
ProductName: Henrik
ProductVersion: 5.09
FileDescription: fletcherized1
OriginalFilename: WINTERANACEAE.exe

Win32/Injector.EBKN also known as:

K7AntiVirusTrojan ( 005441251 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Km2@dCVoAkki
CylanceUnsafe
ZillyaTrojan.Fareit.Win32.29944
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Fareit.738da77e
K7GWTrojan ( 005441251 )
Cybereasonmalicious.2ffe3a
CyrenW32/VBKrypt.GS.gen!Eldorado
SymantecPacked.Generic.535
ESET-NOD32a variant of Win32/Injector.EBKN
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Malware.Fareit-6915600-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.PonyStealer.Km2@dCVoAkki
NANO-AntivirusTrojan.Win32.Fareit.fkqrud
MicroWorld-eScanGen:Heur.PonyStealer.Km2@dCVoAkki
TencentWin32.Trojan-qqpass.Qqrob.Hqbx
Ad-AwareGen:Heur.PonyStealer.Km2@dCVoAkki
SophosMal/Generic-R + Mal/FareitVB-R
ComodoMalware@#fm0f92eombow
BitDefenderThetaGen:NN.ZevbaF.34058.Km2@aCVoAkki
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_FAREIT.THAAOIAH
McAfee-GW-EditionPacked-FNZ!22993312FFE3
FireEyeGeneric.mg.22993312ffe3ad38
EmsisoftGen:Heur.PonyStealer.Km2@dCVoAkki (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.VB.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.28EE250
MicrosoftTrojan:Win32/Vibem.O
ArcabitTrojan.PonyStealer.E7E2AE
GDataGen:Heur.PonyStealer.Km2@dCVoAkki
AhnLab-V3Win-Trojan/VBKrypt.RP05.X1878
McAfeePacked-FNZ!22993312FFE3
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Fareit
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_FAREIT.THAAOIAH
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.PWS.Fareit!kXNXRRng0L4
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EBMZ!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.VB.HwMAEpsA

How to remove Win32/Injector.EBKN?

Win32/Injector.EBKN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment