Malware

About “Win32/Injector.EKCP” infection

Malware Removal

The Win32/Injector.EKCP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKCP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EKCP?


File Info:

crc32: E6FB2D99
md5: f6b59a088af5e6637b76befaaa70ec4f
name: nbchxvjk.exe
sha1: dfc52999f955ad51e8bde310f7317707c7bbd555
sha256: 1051a86dc45f3f29f4de470bf7c1688f138d9ee19f07f743fbb3ddac664f4bcc
sha512: 7db2f5501b531d3a3322cc5824c68c7912a0c0bd9ae1eb892452b567f1637377f37c325ab86516312a569dc4ef31e840b930a2d6f344624e0264f8d97563c79c
ssdeep: 3072:vnijUXFeK4T6MgihEkrlKBuXFeK4T6MgihEkrl9nij:a43ubEM/3ubEMm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: Copyreadu1
InternalName: fourgonsc
FileVersion: 1.00
CompanyName: CHROME
LegalTrademarks: Ankomstpe6
ProductName: ndbrems
ProductVersion: 1.00
OriginalFilename: fourgonsc.exe

Win32/Injector.EKCP also known as:

MicroWorld-eScanTrojan.GenericKD.42276035
FireEyeTrojan.GenericKD.42276035
BitDefenderTrojan.GenericKD.42276035
CyrenW32/Injector.XQ.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EKCP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-7557962-0
Ad-AwareTrojan.GenericKD.42276035
SophosMal/FareitVB-X
BitDefenderThetaGen:NN.ZevbaF.34084.km0@a0qWxakb
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42276035 (B)
ZoneAlarmBackdoor.Win32.NetWiredRC.kcg
AhnLab-V3Trojan/Win32.VBKrypt.C3940082
Acronissuspicious
MAXmalware (ai score=87)
eGambitUnsafe.AI_Score_90%
FortinetW32/Injector.EKCD!tr
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/Injector.EKCP?

Win32/Injector.EKCP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment