Malware

Win32/Injector.EKHD removal

Malware Removal

The Win32/Injector.EKHD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKHD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EKHD?


File Info:

crc32: 168A2491
md5: f1d80545ee284f1e41664220df12f54b
name: notepads.txt
sha1: 4a44916374233fe7dc7a5294ead54568244e58dc
sha256: 3c7ce80a5eed6072f92f17bb19feb940ecc028887b7e3617fb703f4161195bcb
sha512: 16cda519c392001b1c33e193b5cd20460dc324e293b70bb22b9c85cab05343301715b11881a46f80e5d56e2685e4c5837fdc4135b5aa4b1623ba72c77462e059
ssdeep: 768:3dszhzm3AsQ9Av/3l2juuqC5Cuujszhzm3AsQ9Av/3l2:3+cQs133lmunC5CufcQs133l
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Galehusesg
FileVersion: 1.00
CompanyName: Barotr
LegalTrademarks: Besudles1
Comments: Whaledomha
ProductName: MATFUSSHK
ProductVersion: 1.00
OriginalFilename: Galehusesg.exe

Win32/Injector.EKHD also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33008711
FireEyeTrojan.GenericKD.33008711
McAfeeFareit-FRF!F1D80545EE28
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055fa501 )
BitDefenderTrojan.GenericKD.33008711
K7GWTrojan ( 0055fa501 )
CrowdStrikewin/malicious_confidence_60% (W)
F-ProtW32/VBInject.ACR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33008711
KasperskyHEUR:Backdoor.MSIL.NanoBot.vho
AlibabaTrojan:Win32/Vebzenpak.ab42d0cd
NANO-AntivirusTrojan.Win32.Dwn.gycsoq
AegisLabTrojan.Win32.Vebzenpak.4!c
RisingBackdoor.NanoBot!8.28C (CLOUD)
Ad-AwareTrojan.GenericKD.33008711
EmsisoftTrojan.GenericKD.33008711 (B)
DrWebTrojan.DownLoader32.55186
ZillyaTrojan.Vebzenpak.Win32.346
TrendMicroTrojan.Win32.WACATAC.THBOEBO
McAfee-GW-EditionFareit-FRF!F1D80545EE28
MaxSecureTrojan.Malware.74655898.susgen
Trapminemalicious.moderate.ml.score
SophosMal/FareitVB-AA
IkarusTrojan.VB.Crypt
CyrenW32/VBInject.ACR.gen!Eldorado
AviraTR/Injector.ppfva
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Vebzenpak
ArcabitTrojan.Generic.D1F7AC47
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.vho
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Suspicious/Win.VBKrypt.X2058
VBA32BScope.TrojanPSW.MSIL.Agensla
ALYacTrojan.GenericKD.33008711
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKHD
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMD.hp
TencentMsil.Backdoor.Nanobot.Ednk
YandexTrojan.Vebzenpak!
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EETV!tr
BitDefenderThetaGen:NN.ZevbaCO.34106.em0@aiVQjdni
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.c78

How to remove Win32/Injector.EKHD?

Win32/Injector.EKHD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment