Malware

Win32/Injector.EJBK information

Malware Removal

The Win32/Injector.EJBK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Injector.EJBK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Win32/Injector.EJBK?


File Info:

crc32: 283161B0
md5: ba294cd490cae0ec4c817b13905103c6
name: loki7.txt
sha1: a2a8593bc1f65ab1dafc17aee917c06c6e2024a3
sha256: 6f9fb837767dfa4a942fb1c56afba40c29019d0125f2572d45bf15cb175b165e
sha512: 3469ea44a003fb3f62a21cf16c6587106b82ada68a5e036e1b0b8cf5bbdb27f9cf99bea98011411835266b9c3e68bac5c085b777fb1187bf0e79960e4171284c
ssdeep: 6144:0JA7uPw1+51Tt3kaBdDNtYijB6Ndf7UON3A9JWoY:0JM1+d3kaBdDvYvpQ9Mo
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Injector.EJBK also known as:

MicroWorld-eScanGen:Variant.Symmi.93889
FireEyeGeneric.mg.ba294cd490cae0ec
CAT-QuickHealTrojan.Kryptik
McAfeeArtemis!BA294CD490CA
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055bffa1 )
BitDefenderGen:Variant.Symmi.93889
K7GWTrojan ( 0055bffa1 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
BitDefenderThetaGen:NN.ZelphiF.32253.rmGfa0uq2jii
F-ProtW32/Injector.IOW
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Symmi.93889
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Injector.9f464df2
RisingPUF.InstallCore!8.8B (TFE:5:Q1cmzwBqmaI)
Ad-AwareGen:Variant.Symmi.93889
F-SecureTrojan.TR/Injector.mpclf
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
Trapminemalicious.high.ml.score
SophosMal/Fareit-V
IkarusTrojan.Agent
CyrenW32/Injector.CWOI-2362
JiangminTrojan.Kryptik.zc
AviraTR/Injector.mpclf
Endgamemalicious (moderate confidence)
ArcabitTrojan.Symmi.D16EC1
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Lokibot.CS!MTB
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
ALYacGen:Variant.Symmi.93889
MAXmalware (ai score=82)
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EJBK
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
FortinetW32/Agent.AJFK!tr
AVGFileRepMalware
Cybereasonmalicious.bc1f65
Qihoo-360Win32/Trojan.469

How to remove Win32/Injector.EJBK?

Win32/Injector.EJBK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment