Malware

About “Win32/Injector.EJGG” infection

Malware Removal

The Win32/Injector.EJGG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EJGG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EJGG?


File Info:

crc32: 8CB4B608
md5: fc8aa8e5ba73fa0980f3404f9a8abfab
name: naturez.exe
sha1: 3660705b8ed5970796b9d3d4263d681a2a1915c9
sha256: 88f8632825710a5ce3b877b650d066b89b4c01da7e0d5496d747e92410952906
sha512: e493b8e64063d7dbb90525d2f4364890964e744c58f16d79e6fc492e684d5f8cbd3acb9164be0d747ebcbc57f3377cfaf11fda77f3c7842ece85eb74c9dd3398
ssdeep: 24576:0qrcHcr6FnQI5+INCoyg8iBAmUyyTe+peBGetDAsR1N:0qsGIFSi2mUyueH9x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EJGG also known as:

FireEyeGeneric.mg.fc8aa8e5ba73fa09
McAfeeGenericRXGM-EJ!FC8AA8E5BA73
CylanceUnsafe
Cybereasonmalicious.b8ed59
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.32515.@GW@aKD2gOpi
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Trojan.Win32.Vimditator.gen
RisingTrojan.Generic@ML.90 (RDML:1q75Jrzt6WGcVNMOz9jj9A)
Endgamemalicious (high confidence)
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.fh
Trapminemalicious.high.ml.score
ZoneAlarmHEUR:Trojan.Win32.Vimditator.gen
AhnLab-V3Win-Trojan/Delphiless02.Exp
Acronissuspicious
MalwarebytesTrojan.MalPack.DLF
ESET-NOD32a variant of Win32/Injector.EJGG
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
FortinetW32/Agent.AJFK!tr
Qihoo-360HEUR/QVM05.1.8E23.Malware.Gen

How to remove Win32/Injector.EJGG?

Win32/Injector.EJGG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment