Malware

Win32/Injector.EJET (file analysis)

Malware Removal

The Win32/Injector.EJET is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EJET virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.EJET?


File Info:

crc32: 592474CF
md5: e76d9d231d1127d60772de3ad4b8c45c
name: tif.exe
sha1: a985f555d5f8e112d4d81b0ddb7a077c7545f7bf
sha256: e7518d9056e8ca03fa29a5de7bb562b4f612f2062157cdac61ab14ae8b607510
sha512: b94ef530bcc60317d2c7fb132648d0ade06a71cf6f2656de9155f877ccc8fe28d03db49e9fef9ba7993a7db03c6ac0e0e04f23fe8e85b37e9135b0fe71860722
ssdeep: 12288:ZB7GHyoYEiRIxh8fNC6YpNFR8HiWmdCVttw6AjC15Pgw0Rf6:CDYVWedGFaCsTsj+5oXQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EJET also known as:

MicroWorld-eScanTrojan.Agent.EIGU
FireEyeGeneric.mg.e76d9d231d1127d6
CAT-QuickHealTrojan.Lokibot
McAfeeFareit-FQP!E76D9D231D11
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Eigu.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.EIGU
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.31d112
Invinceaheuristic
F-ProtW32/Injector.IPJ
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.Agent.EIGU
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Lokibot.316ec6aa
NANO-AntivirusTrojan.Win32.TrjGen.gjxfzf
RisingTrojan.Generic@ML.84 (RDMK:ZMe8EN/hnz3xQZC3iKgfmg)
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.EIGU (B)
ComodoTrojWare.Win32.TrojanDownloader.Dadobra.~JH7@1ql0d4
F-SecureTrojan.TR/Injector.ftnfi
DrWebTrojan.PWS.Stealer.26517
ZillyaTrojan.Injector.Win32.669984
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
Trapminemalicious.high.ml.score
SophosMal/Fareit-V
IkarusTrojan.Inject
CyrenW32/Injector.JKCI-2642
JiangminTrojan.Kryptik.zj
WebrootW32.Trojan.Gen
AviraTR/Injector.ftnfi
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Agent.EIGU
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Lokibot.E!MTB
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacSpyware.LokiBot
Ad-AwareTrojan.Agent.EIGU
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
ZonerTrojan.Win32.84407
ESET-NOD32a variant of Win32/Injector.EJET
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.AJFK!tr
BitDefenderThetaGen:NN.ZelphiF.33550.3GW@auxOtJli
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.b79

How to remove Win32/Injector.EJET?

Win32/Injector.EJET removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment