Malware

Win32/Injector.EHQD removal instruction

Malware Removal

The Win32/Injector.EHQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EHQD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Detects VirtualBox through the presence of a file

How to determine Win32/Injector.EHQD?


File Info:

name: 48F23D11032338721A13.mlw
path: /opt/CAPEv2/storage/binaries/d37e34bb71db2c91de926dac8d39af3edec4e101c9f9e08caa80219d6d1b98bc
crc32: 3503FF7B
md5: 48f23d11032338721a133272d827b1e9
sha1: 3b6382356aa5bd9abac07385f203d932e7e91e32
sha256: d37e34bb71db2c91de926dac8d39af3edec4e101c9f9e08caa80219d6d1b98bc
sha512: c73301870aa06380ee68b7b26799b7b43b7e58f9372e296633650b7660756d53b41b8f3783f824045bfb31b5b6e378c7820ea19e207dbaca2f6d56e7efa32b4b
ssdeep: 6144:5QUO5vR5j+OaCkNGWDFUcZ3DPfOJRRzxzFFq5v8hknorKpoNzNejvgMtTrQPbp3T:5QUO51a1lejzFWbYSoBN7Tp3T/Jl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8A46B41B1E090B6FCA51571E1AA6BBF4C387E80572195CB33E81D9C0BB06E295F5FA3
sha3_384: b5e8a46468c3bf00e90d21a883f44369a695f14a2e94140b078e050700a4833d511d1ad187fabecc9e1c35887bef23df
ep_bytes: e8ac040000e97afeffff558bec81ec24
timestamp: 2021-12-05 00:05:27

Version Info:

0: [No Data]

Win32/Injector.EHQD also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!C3442172AC97
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.103233
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EHQD
APEXMalicious
BitDefenderGen:Heur.Mint.Zard.42
MicroWorld-eScanGen:Heur.Mint.Zard.42
Ad-AwareGen:Heur.Mint.Zard.42
SophosMal/Wonton-S
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.48f23d1103233872
EmsisoftGen:Heur.Mint.Zard.42 (B)
GDataGen:Heur.Mint.Zard.42
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
ArcabitTrojan.Mint.Zard.42
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Heur.Mint.Zard.42
VBA32BScope.Trojan.Inject
RisingTrojan.Generic@ML.100 (RDML:HFmcPEpevsEUdL7RQQRiFQ)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_73%
FortinetW32/Kryptik.GXZM!tr
BitDefenderThetaGen:NN.ZexaF.34062.DuW@aeYQZsgO
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.EHQD?

Win32/Injector.EHQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment