Malware

Win32/Injector.EJBT removal tips

Malware Removal

The Win32/Injector.EJBT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Injector.EJBT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.EJBT?


File Info:

crc32: 0C3344A5
md5: 654cff8cab6eb335e768f446e2bf31b6
name: loki6.exe
sha1: 36cbebcd5a24da40492b0817eceec968734d21dd
sha256: 6b316a9219cbb0b83a1799bb1a324bbcb3f379c90f5096ed5a28a2020875488d
sha512: 54ace2b43cc55e09e02cd194aa1be544c5c83d73bc070e4afa8f386b8998442d479a413680658cb34c2480664cf6af1cf0a1e0dceb7f61c6eb67d02170ab51dd
ssdeep: 6144:fspny4P2kffDv7umgzPnQDFbvUl2xWLS5NMCQybOzE6NddTgJGjUgBqkOFgbN:kpJfDzumkPiFbu2xusNfbPGjROFQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Injector.EJBT also known as:

MicroWorld-eScanGen:Variant.Symmi.93889
FireEyeGeneric.mg.654cff8cab6eb335
CAT-QuickHealTrojan.Kryptik
McAfeeArtemis!654CFF8CAB6E
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Symmi.93889
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.32253.qmGfaWnIdzfi
F-ProtW32/Injector.IOY
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
Paloaltogeneric.ml
GDataGen:Variant.Symmi.93889
KasperskyTrojan.Win32.Kryptik.vo
RisingTrojan.GenKryptik!8.AA55 (TFE:5:WonrEgPV5sG)
Ad-AwareGen:Variant.Symmi.93889
ComodoMalware@#rqx58v7lnifm
F-SecureTrojan.TR/Kryptik.caozp
DrWebTrojan.Siggen8.57744
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
McAfee-GW-EditionBehavesLike.Win32.Worm.dc
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
SophosMal/Fareit-V
APEXMalicious
CyrenW32/Injector.TDEA-8295
JiangminTrojan.Kryptik.yz
AviraTR/Kryptik.caozp
Endgamemalicious (moderate confidence)
ArcabitTrojan.Symmi.D16EC1
ZoneAlarmTrojan.Win32.Kryptik.vo
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
ALYacGen:Variant.Symmi.93889
MAXmalware (ai score=100)
CylanceUnsafe
ESET-NOD32a variant of Win32/Injector.EJBT
IkarusTrojan.Agent
FortinetW32/GenKryptik.CJOK!tr
AVGFileRepMalware
Cybereasonmalicious.d5a24d
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.469

How to remove Win32/Injector.EJBT?

Win32/Injector.EJBT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment