Malware

Win32/Injector.EJGZ removal guide

Malware Removal

The Win32/Injector.EJGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EJGZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EJGZ?


File Info:

crc32: 9D8B93D4
md5: 4d460be0f73c568f687a05839cb3eb1d
name: 1.exe
sha1: aefb0f2b2844be225ae9ea075e68f057632556d0
sha256: 4f71844ecf1f290983515abb75804e6a6615a37536acbd10f267679feecaa9fd
sha512: 1fbd29c8cd7b83dffae2b58f486a9ec5489b2fea9c324210c519c46caf420c8d4756eb8790a7fc13ae069bbda6c3c88d3ed4dcab2b1e6184356adaf6c4fd30af
ssdeep: 12288:E1HZR1HZuo3mXq2FyFYp365z3okRa/3/PcBeK2b0JM4W15Afg7EWpwJK6kHfsCL:Lq5A3SckEXc4K2b0J85ygAK6k/sCVJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x03fc 0x04b0
InternalName: zruCIOLATO
FileVersion: 6.00
CompanyName: asUS
ProductName: sirOEFFECT1
ProductVersion: 6.00
OriginalFilename: zruCIOLATO.exe

Win32/Injector.EJGZ also known as:

MicroWorld-eScanTrojan.GenericKD.42076795
FireEyeGeneric.mg.4d460be0f73c568f
CAT-QuickHealTrojan.Chapak
ALYacTrojan.GenericKD.42076795
MalwarebytesTrojan.MalPack.VB
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Chapak.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42076795
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b2844b
BitDefenderThetaGen:NN.ZevbaF.32519.hn0@ayiWt!kG
CyrenW32/Trojan.TXUJ-3994
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-7426416-0
GDataTrojan.GenericKD.42076795
KasperskyTrojan.Win32.Chapak.efzi
NANO-AntivirusTrojan.Win32.Dwn.gkgiko
ViRobotTrojan.Win32.Z.Highconfidence.1163264
Ad-AwareTrojan.GenericKD.42076795
EmsisoftTrojan-Spy.Agent (A)
ComodoMalware@#2rufzpyslkvhu
F-SecureTrojan.TR/Kryptik.amrlf
DrWebTrojan.DownLoader30.47765
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
SophosMal/FareitVB-X
IkarusTrojan.VB.Crypt
F-ProtW32/Kryptik.ATB.gen!Eldorado
JiangminTrojan.Chapak.iby
AviraTR/Kryptik.amrlf
Antiy-AVLTrojan/Win32.Chapak
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D2820A7B
ZoneAlarmTrojan.Win32.Chapak.efzi
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Injector.R302187
Acronissuspicious
McAfeeFareit-FPZ!4D460BE0F73C
ESET-NOD32a variant of Win32/Injector.EJGZ
TrendMicro-HouseCallTROJ_GEN.R002C0PL319
SentinelOneDFI – Malicious PE
FortinetW32/Malicious_Behavior.VEX
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.44c

How to remove Win32/Injector.EJGZ?

Win32/Injector.EJGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment