Malware

How to remove “Win32/Injector.EJSN”?

Malware Removal

The Win32/Injector.EJSN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EJSN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EJSN?


File Info:

crc32: A1C12C75
md5: 94f461cd91111718a7d69cf318edba12
name: 9e03399f79c6e2c36dbe3192cc1e3791562b56c1efd2323537c65722849b6b7a
sha1: da1f13f01806859d1acdb902d3eb1e99d7a13a6e
sha256: 9e03399f79c6e2c36dbe3192cc1e3791562b56c1efd2323537c65722849b6b7a
sha512: 711eaf5ab86fbe94cc4b6cd5c203b2419a586e30c4915815516381365e41968fc16ca21c8d273c6d78a6c6aec560e10ce4ad4034f7ca511373f09e407fdd93fe
ssdeep: 384:28B5bOZxbBjU4xUGkYxZqADvGiMAD2UBsYUSRpvc42h:HB5YxbBjU4dzOiMdIUWvcB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Sborg
FileVersion: 4.05.0001
CompanyName: sovebeslagets
LegalTrademarks: Coatede4
ProductName: CUBITALE
ProductVersion: 4.05.0001
OriginalFilename: Sborg.exe

Win32/Injector.EJSN also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33017617
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKD.33017617
CylanceUnsafe
AegisLabTrojan.MSIL.NanoBot.m!c
K7AntiVirusTrojan ( 0055e5011 )
BitDefenderTrojan.GenericKD.33017617
K7GWTrojan ( 0055e5011 )
TrendMicroTROJ_GEN.R011C0WB320
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Trojan.VBGeneric-7528480-0
GDataTrojan.GenericKD.33017617
KasperskyBackdoor.MSIL.NanoBot.azbm
AlibabaBackdoor:MSIL/NanoBot.9c0c85e8
NANO-AntivirusTrojan.Win32.Dwn.gycwow
ViRobotTrojan.Win32.Z.Injector.36864.ABY
RisingBackdoor.NanoBot!8.28C (CLOUD)
Ad-AwareTrojan.GenericKD.33017617
EmsisoftTrojan.GenericKD.33017617 (B)
ComodoMalware@#nvjwmha419hc
F-SecureTrojan.TR/Injector.hrjwi
DrWebTrojan.DownLoader32.55538
ZillyaTrojan.Injector.Win32.682566
McAfee-GW-EditionPacked-FZN!94F461CD9111
FireEyeTrojan.GenericKD.33017617
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
CyrenW32/Trojan.SEOG-4358
JiangminBackdoor.MSIL.clul
AviraTR/Injector.hrjwi
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/MSIL.NanoBot
ArcabitTrojan.Generic.D1F7CF11
ZoneAlarmBackdoor.MSIL.NanoBot.azbm
MicrosoftTrojan:Win32/Occamy.C
McAfeeArtemis!94F461CD9111
TACHYONBackdoor/W32.VB-NanoBot.36864
VBA32TScope.Trojan.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EJSN
TrendMicro-HouseCallTROJ_GEN.R011C0WB320
TencentMsil.Backdoor.Nanobot.Hvsu
YandexBackdoor.NanoBot!
FortinetW32/EJSN!tr
BitDefenderThetaGen:NN.ZevbaCO.34100.cm0@amOwhxpi
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Backdoor.BO.6f2

How to remove Win32/Injector.EJSN?

Win32/Injector.EJSN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment