Malware

Win32/Injector.EDQY (file analysis)

Malware Removal

The Win32/Injector.EDQY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EDQY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Macau)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Injector.EDQY?


File Info:

crc32: 44ADED3C
md5: 31a073d814f3cde543637653c2071e98
name: 31A073D814F3CDE543637653C2071E98.mlw
sha1: 5278f17d576c8af3b49e4fd051aa90e70307921b
sha256: 38a9ca2dd2c76f121d809cecc5dc24cba1dd71c941e6d637c37253bbdb5d2318
sha512: 89a3a7612c2d7c16219886d5f04c07aba5ced64eeb0707c5451555b4a609080f4d1c9f1bb7c5adc9c4f494c58fc8b21035301cac1677edf627431ab98b5717f3
ssdeep: 6144:cYKbjssSjbH9z5Ejf3liXZx+/3Z5fU3pH29:rcjIjbja/liP+/7cZW9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: intEvaTion gmbH
InternalName: anglicans
FileVersion: 1.00
LegalTrademarks: intEvaTion gmbH
Comments: intEvaTion gmbH
ProductName: intEvaTion gmbH
ProductVersion: 1.00
FileDescription: intEvaTion gmbH
OriginalFilename: anglicans.exe

Win32/Injector.EDQY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Remcos.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.12810
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.wm0@d8Uev2bb
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.24721
SangforBackdoor.Win32.Remcos.bnx
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Remcos.7dbdbf88
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.814f3c
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EDQY
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Dropper.Remcos-6857978-0
KasperskyBackdoor.Win32.Remcos.bnx
BitDefenderGen:Heur.PonyStealer.wm0@d8Uev2bb
NANO-AntivirusTrojan.Win32.Remcos.fnanyk
MicroWorld-eScanGen:Heur.PonyStealer.wm0@d8Uev2bb
TencentWin32.Backdoor.Remcos.Ljae
Ad-AwareGen:Heur.PonyStealer.wm0@d8Uev2bb
SophosMal/Generic-S
ComodoMalware@#336l34krzhktg
BitDefenderThetaGen:NN.ZevbaF.34236.wm0@a8Uev2bb
VIPRELooksLike.Win32.Malware!vb (v)
TrendMicroBackdoor.Win32.REMCOS.THBADAI
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.31a073d814f3cde5
EmsisoftGen:Heur.PonyStealer.wm0@d8Uev2bb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Remcos.ga
WebrootW32.Malware.Mlpe
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.2A92347
MicrosoftPWS:Win32/Aicat.A!ml
GDataGen:Heur.PonyStealer.wm0@d8Uev2bb
AhnLab-V3Trojan/Win32.Inject.C3025401
McAfeeGenericRXKB-JU!31A073D814F3
MAXmalware (ai score=89)
VBA32Backdoor.Remcos
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.REMCOS.THBADAI
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!HPBtzFdMcvg
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.74390566.susgen
FortinetW32/Injector.EDQY!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Remcos.HwMAEpsA

How to remove Win32/Injector.EDQY?

Win32/Injector.EDQY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment