Malware

Should I remove “Win32/Injector.EIRH”?

Malware Removal

The Win32/Injector.EIRH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EIRH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Injector.EIRH?


File Info:

name: 6916053479217DACE6C4.mlw
path: /opt/CAPEv2/storage/binaries/96ec891e1c084649551f5a7f6eed7915042bad7a424462a055f906771313838c
crc32: 35966189
md5: 6916053479217dace6c44ac6ef8bdcd1
sha1: 3df8a748641baacd511dfb4df6a21e2c23cf0150
sha256: 96ec891e1c084649551f5a7f6eed7915042bad7a424462a055f906771313838c
sha512: e0dc6014aa1e8bf40352d71b76b56a29e4868245926c7ee0b47fdfcdbf5741ed70b5d397d4781f77d4b702614c58f3c644e2e25049d4fc295380c62c6a46512c
ssdeep: 6144:mDAk6COlzFZn6O4yBjZ62Bai6ddO8OpUV:mDD6FHxBaiwvOpI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D25F13729635AB5E90A5AFD5D5A0EBC422FFC122B7007BF411C352D39232B03AA061F
sha3_384: f7f88566c4f0a2476ac6fb9102d1b32ded65506286ac886d1d36356653810d8a401aedd9f009c17c2ecb40df60a9d582
ep_bytes: 6884234000e8f0ffffff000000000000
timestamp: 2013-09-19 10:32:34

Version Info:

Translation: 0x0404 0x04b0
ProductName: Typehuset
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Handicappene2
OriginalFilename: Handicappene2.exe

Win32/Injector.EIRH also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.an3@vGY4jOdb
FireEyeGeneric.mg.6916053479217dac
ALYacGen:Heur.PonyStealer.an3@vGY4jOdb
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055ac2f1 )
AlibabaTrojan:Win32/Injector.3c9db655
K7GWTrojan ( 0055ac2f1 )
Cybereasonmalicious.479217
VirITTrojan.Win32.VBPack_Heur
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EIRH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.PonyStealer.an3@vGY4jOdb
NANO-AntivirusTrojan.Win32.Inject4.jjdxdw
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Wnmk
Ad-AwareGen:Heur.PonyStealer.an3@vGY4jOdb
SophosMal/Generic-S
DrWebTrojan.Inject4.21836
TrendMicroTROJ_GEN.R002C0WLA21
McAfee-GW-EditionBehavesLike.Win32.Trojan.tz
EmsisoftGen:Heur.PonyStealer.an3@vGY4jOdb (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.PonyStealer.an3@vGY4jOdb
AviraHEUR/AGEN.1132083
Antiy-AVLTrojan/Win32.Injector
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeRDN/Generic.rp
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.FL
TrendMicro-HouseCallTROJ_GEN.R002C0WLA21
YandexTrojan.Agent!Jgc08HXtbtk
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_94%
FortinetW32/Injector.EIXY!tr
BitDefenderThetaGen:NN.ZevbaF.34084.an3@aGY4jOdb
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.EIRH?

Win32/Injector.EIRH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment