Malware

Win32/Injector.EEMG information

Malware Removal

The Win32/Injector.EEMG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EEMG virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EEMG?


File Info:

crc32: E16F74B2
md5: d678eae52bd8c936023c6d999e9d05b6
name: D678EAE52BD8C936023C6D999E9D05B6.mlw
sha1: 740660ba50dfdd059c15f96da03ffc4f7589f75c
sha256: eef116dd4949044c545efb5105e27eb1c90a97c94590efde9f15e67fd8fc9ee8
sha512: 8363a51dee8230958596416a95dcf13dcaa20446400af95cbc7dca63f1af8e7ffdc65d0410473c5c5ea4f0ca5cc36ff012e03e3807333800c98aff3e93671ccc
ssdeep: 24576:FpkpHmW7ovIuFakNpaCw9muDwwcA5vNOCxRkkQjfWfSKTM8lk9ZRyeYJUUQwTlvu:vkdpsvIuFa+e9muDwwcA5vNOCxRkkQj3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: UNIXB
FileVersion: 7.03.0009
CompanyName: jozy4
Comments: Bewhig
ProductName: LUMBERERS
ProductVersion: 7.03.0009
FileDescription: dcna
OriginalFilename: UNIXB.exe

Win32/Injector.EEMG also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.49392
MicroWorld-eScanGen:Heur.PonyStealer.8m1@hipTANli
FireEyeGeneric.mg.d678eae52bd8c936
Qihoo-360HEUR/QVM03.0.38DF.Malware.Gen
McAfeePacked-FRZ!D678EAE52BD8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Heur.PonyStealer.8m1@hipTANli
Cybereasonmalicious.52bd8c
InvinceaML/PE-A
BitDefenderThetaGen:NN.ZevbaF.34590.8m1@aipTANli
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Dropper.Razy-6911761-0
KasperskyTrojan.Win32.VBKryjetor.bpyu
RisingTrojan.Injector!1.B459 (CLASSIC)
Ad-AwareGen:Heur.PonyStealer.8m1@hipTANli
F-SecureHeuristic.HEUR/AGEN.1121314
TrendMicroTrojanSpy.Win32.FAREIT.SMA1.hp
McAfee-GW-EditionPacked-FRZ!D678EAE52BD8
EmsisoftGen:Heur.PonyStealer.8m1@hipTANli (B)
IkarusTrojan.Crypt.Malcert
AviraHEUR/AGEN.1121314
MAXmalware (ai score=81)
MicrosoftVirTool:Win32/VBInject.ADH!bit
ArcabitTrojan.PonyStealer.EF7C39
ZoneAlarmTrojan.Win32.VBKryjetor.bpyu
GDataGen:Heur.PonyStealer.8m1@hipTANli
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP08.X1976
VBA32TScope.Trojan.VB
ALYacGen:Heur.PonyStealer.8m1@hipTANli
MalwarebytesTrojan.MalPack.VB.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EEMG
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMA1.hp
YandexTrojan.VBKryjetor!4ukp9fsT7Go
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Injector.EHGX!tr
AVGWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.EEMG?

Win32/Injector.EEMG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment