Malware

How to remove “Win32/Injector.EJUF”?

Malware Removal

The Win32/Injector.EJUF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EJUF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EJUF?


File Info:

crc32: 38C196BC
md5: e4f37276075eb61ef46a02dd4732d4ed
name: 1.exe
sha1: dad21d20843fb4097ce9959591bedae54b34cc32
sha256: c16c6ba980f01ad233ac8c699a740383a19a50d961133f249f6a9d7b25f9f8c9
sha512: b4472b4bcb53a5bdfb2e6764e9cedffc9b1b4e36b9a903f384a01289a06da5b4b1ceda439f2acdc3ba293b21139b86a44d3338e3a9cf1e0b2724c28741b2e736
ssdeep: 3072:Kpy+bnr+O1S5GWp1icKAArDZz4N9GhbkrNEk1j704soy:Kpy+bnr+tp0yN90QE475j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Win32/Injector.EJUF also known as:

MicroWorld-eScanTrojan.GenericKD.32926652
McAfeeRDN/Generic.tfr
MalwarebytesTrojan.Injector
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e7f01 )
BitDefenderTrojan.GenericKD.32926652
K7GWTrojan ( 0055e7f01 )
CrowdStrikewin/malicious_confidence_60% (W)
ArcabitTrojan.Generic.D1F66BBC
Invinceaheuristic
F-ProtW32/Remcos.B.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EJUF
Paloaltogeneric.ml
KasperskyTrojan.Win32.Crypt.ajuj
AlibabaTrojan:Win32/Injector.58c53690
TencentWin32.Trojan.Crypt.Amlv
Ad-AwareTrojan.GenericKD.32926652
EmsisoftTrojan.GenericKD.32926652 (B)
F-SecureTrojan.TR/Injector.euyav
McAfee-GW-EditionBehavesLike.Win32.Dropper.dm
FortinetW32/EJUF!tr
FireEyeGeneric.mg.e4f37276075eb61e
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
CyrenW32/Remcos.B.gen!Eldorado
WebrootW32.Malware.Gen
AviraTR/Injector.euyav
MAXmalware (ai score=99)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmTrojan.Win32.Crypt.ajuj
ALYacBackdoor.Remcos.A
CylanceUnsafe
PandaTrj/CI.A
RisingTrojan.Injector!8.C4 (CLOUD)
eGambitUnsafe.AI_Score_67%
GDataTrojan.GenericKD.32926652
AVGFileRepMalware
Cybereasonmalicious.0843fb
AvastFileRepMalware
Qihoo-360Trojan.Generic

How to remove Win32/Injector.EJUF?

Win32/Injector.EJUF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment