Malware

Win32/Injector.EBQH information

Malware Removal

The Win32/Injector.EBQH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EBQH virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system

Related domains:

pastebin.com
cutit.org
q.gs
aporasal.net

How to determine Win32/Injector.EBQH?


File Info:

crc32: 56178686
md5: 24380dfeff1ca1fc1e64995fcfbca2e4
name: 24380DFEFF1CA1FC1E64995FCFBCA2E4.mlw
sha1: 3fa1b26e86b45b7163e2960ce2ec0c4f096988dc
sha256: 3a9052f71200c79827e551113abc41af09d21f327dad1689034f0ad4e62dacf7
sha512: 988094986ebbcf6e849ba1c0d1c527449ac7a3c679fcd24c2ee77e6a54b143dfe09db4b8d263e154bb4c739cf2729416dd610feb275883b997d767dcc1138eb0
ssdeep: 24576:Rx7KGLjTBwgkJz2fN9kTLdKigD6rRSHse:RsSjTBwgkl2fXkTLdAD6rwHz
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Injector.EBQH also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.576052
CAT-QuickHealTrojan.Generic
Qihoo-360HEUR/QVM19.1.057B.Malware.Gen
ALYacGen:Variant.Razy.576052
CylanceUnsafe
ZillyaTrojan.Injector.Win32.804166
SangforMalware
K7AntiVirusTrojan ( 0057372a1 )
BitDefenderGen:Variant.Razy.576052
K7GWTrojan ( 0057372a1 )
Cybereasonmalicious.eff1ca
CyrenW32/S-91c2cc44!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Razy.idvieo
RisingTrojan.Injector!1.C865 (CLASSIC)
Ad-AwareGen:Variant.Razy.576052
EmsisoftGen:Variant.Razy.576052 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1136878
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.24380dfeff1ca1fc
SophosML/PE-A + Troj/Agent-BFYM
IkarusTrojan.Win32.Injector
JiangminTrojan.Generic.gmxly
AviraHEUR/AGEN.1136878
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Razy.D8CA34
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.576052
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R263763
McAfeeGenericRXMX-YR!24380DFEFF1C
VBA32BScope.Trojan.Wacatac
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.EBQH
TrendMicro-HouseCallPAK_Xed-10
TencentMalware.Win32.Gencirc.11b28945
YandexTrojan.Injuke!2yU81wyN//Q
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
FortinetW32/Injector.EBQH!tr
BitDefenderThetaGen:NN.ZexaF.34804.ZmZ@aa@cnPk
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.EBQH?

Win32/Injector.EBQH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment