Malware

Should I remove “Win32/Injector.EKJS”?

Malware Removal

The Win32/Injector.EKJS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKJS virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

mikeservers.eu

How to determine Win32/Injector.EKJS?


File Info:

crc32: 32A8ABCE
md5: 4656ddb2c96508e472ffe43dcba01fcb
name: kingz.exe
sha1: 3546e4c7d94fe9f57eaecdc6b4d409529c048fc8
sha256: e59c6ce877c0add444ec2b2e91d5384a5659ea5cb5b74d113256168b8abddc17
sha512: b7dff05f4f4e95afeeb6f879451bcc81eb952465bd567636952b2344cb2fce85034c9cbaa1fe95ae8aefb3bfc2731024e08108be09ce128a6a7cfe90330094c1
ssdeep: 12288:VINPjUG7HLgmK/s6CKKMmxfZBENA4/SY5IRWVNSVgLKJ/fuVotb8S2bmDDKax:VEPp7XK/s6PmxhF4/v1oJ/frGS7DKax
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EKJS also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.PWS.Stealer.23680
MicroWorld-eScanTrojan.GenericKD.33039962
FireEyeGeneric.mg.4656ddb2c96508e4
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33039962
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZelphiF.34084.SGW@aaNvzUmi
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.33039962
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/GenKryptik.184b1f5f
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33039962 (B)
F-SecureTrojan.TR/Injector.ghxok
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.bh
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.high.ml.score
SophosMal/Fareit-V
IkarusTrojan.Win32.Injector
CyrenW32/Trojan.IGIN-2949
WebrootW32.Adware.Gen
AviraTR/Injector.ghxok
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1F8265A
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
McAfeeFareit-FRB!4656DDB2C965
MalwarebytesTrojan.MalPack.DLF
ESET-NOD32a variant of Win32/Injector.EKJS
eGambitUnsafe.AI_Score_64%
FortinetW32/Injector.DZGI!tr
Ad-AwareTrojan.Agent.ELEG
AVGFileRepMalware
Cybereasonmalicious.7d94fe
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM05.1.09C3.Malware.Gen

How to remove Win32/Injector.EKJS?

Win32/Injector.EKJS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment