Categories: Malware

Win32/Injector.EIVT removal guide

The Win32/Injector.EIVT file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Injector.EIVT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.EIVT?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Trojan:Win32/Skeeyah.A!MTB

File Info:

Name: meka.exe

Size: 733184

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: a43f97001dc5180e1c72da7d6affb244

SHA1: ba1f12b8186500da82d11698442224f2278a8231

SH256: 41b0dc912fc6f643bf2719b826acaa159143b637d435379463a959ad97db2d14

Version Info:

[No Data]

Win32/Injector.EIVT also known as:

ALYac Spyware.LokiBot
APEX Malicious
AVG Win32:CrypterX-gen [Trj]
Ad-Aware Gen:Variant.Strictor.231497
AegisLab Trojan.Win32.Crypt.4!c
AhnLab-V3 Malware/Win32.Generic.C3558899
Alibaba Trojan:Win32/GenKryptik.d350366b
Antiy-AVL Trojan/Win32.Crypt
Arcabit Trojan.Strictor.D38849
Avast Win32:CrypterX-gen [Trj]
Avira TR/Kryptik.qqobb
BitDefender Gen:Variant.Strictor.231497
Comodo Malware@#1g6q1opjkqi0m
CrowdStrike win/malicious_confidence_60% (W)
Cylance Unsafe
Cyren W32/Injector.BMXR-4774
DrWeb Trojan.PWS.Stealer.27390
ESET-NOD32 a variant of Win32/Injector.EIVT
F-Prot W32/Injector.IOL
F-Secure Trojan.TR/Kryptik.qqobb
FireEye Generic.mg.a43f97001dc5180e
Fortinet W32/GenKryptik.DXIV!tr
GData Win32.Trojan-Stealer.LokiBot.J9HX18
Ikarus Trojan.Inject
K7AntiVirus Trojan ( 0055b3a11 )
K7GW Trojan ( 0055b3a11 )
Kaspersky HEUR:Trojan.Win32.Crypt.gen
MAX malware (ai score=100)
Malwarebytes Trojan.MalPack.SMY.Generic
MaxSecure Trojan.Malware.10374761.susgen
McAfee GenericRXJB-OW!A43F97001DC5
McAfee-GW-Edition BehavesLike.Win32.Fareit.bc
MicroWorld-eScan Gen:Variant.Strictor.231497
Microsoft Trojan:Win32/Skeeyah.A!MTB
NANO-Antivirus Trojan.Win32.Palevo.ggyeyu
Paloalto generic.ml
Panda Trj/GdSda.A
Rising Trojan.Generic@ML.81 (RDML:7Q1Z0ILZA9WuwJfHw1oNcQ)
Sophos Mal/Generic-S
Symantec Trojan Horse
Trapmine suspicious.low.ml.score
TrendMicro TROJ_GEN.R002C0WKC19
TrendMicro-HouseCall TROJ_GEN.R002C0WKC19
VBA32 TScope.Trojan.Delf
VIPRE Trojan.Win32.Generic!BT
Webroot W32.Trojan.Gen
Yandex Trojan.Crypt!T/VwjYG/BwQ
ZoneAlarm HEUR:Trojan.Win32.Crypt.gen

How to remove Win32/Injector.EIVT?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

2 months ago