Malware

Win32/Injector.EJNL malicious file

Malware Removal

The Win32/Injector.EJNL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EJNL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EJNL?


File Info:

crc32: 73F19655
md5: ee2a243130c63629a63a88e979219a05
name: ugopoundz.exe
sha1: 8256d7925cfe1208071bf19095abbca61de48892
sha256: 94cdb5ee272fb3f26c54f1efae7b9db7a648296241ba8c775c16e8dcdae1d9a3
sha512: ff01701378360a15c08b6be6d9cf4764b6951386131f788a2b4dc26ac6df09d150f68af225f3952d321ec1376f79724ba451d9e1451293bf1fb0a6deab0444cd
ssdeep: 12288:qK71Yam0rWXWtIHAJATeRRPBJFiW0cw9ykreJUuU1ZWZiO71sb2+vgxF:ezt2IHyA4FxiW0/ykri4SEOg2Ogx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EJNL also known as:

MicroWorld-eScanTrojan.GenericKD.32819014
McAfeeFareit-FQP!EE2A243130C6
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32819014
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.D1F4C746
TrendMicroTSPY_HPLOKI.SMBD
F-ProtW32/Injector.IQQ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EJNL
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Crypt.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
NANO-AntivirusTrojan.Win32.TrjGen.gluxxj
RisingTrojan.Generic@ML.100 (RDML:fVJh//VN2EoF1xBlGBig+g)
Ad-AwareTrojan.GenericKD.32819014
EmsisoftTrojan.GenericKD.32819014 (B)
ComodoMalware@#1q7eet3l2uej5
F-SecureTrojan.TR/Injector.dzdli
DrWebTrojan.Siggen8.63306
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.ee2a243130c63629
SophosMal/Generic-S
CyrenW32/Trojan.VPPT-1786
AviraTR/Injector.dzdli
FortinetW32/Agent.AJFK!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Lokibot.ART!eml
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
AhnLab-V3Win-Trojan/Delphiless.Exp
ALYacTrojan.Agent.FormBook
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPLOKI.SMBD
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
GDataTrojan.GenericKD.32819014
BitDefenderThetaGen:NN.ZelphiF.33556.2GX@aCStugni
AVGWin32:Trojan-gen
Cybereasonmalicious.25cfe1
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ed1

How to remove Win32/Injector.EJNL?

Win32/Injector.EJNL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment