Malware

Win32/Injector.EKMF information

Malware Removal

The Win32/Injector.EKMF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKMF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.EKMF?


File Info:

crc32: 6275A6FA
md5: b881e19d5babbea09539affcb89464fa
name: 1222896.exe
sha1: 99e0c781707343d2617d36bf6ac232c0ec129ba9
sha256: 90e9c7c08bac2a9926a1036df6bd2ca1f1a652425844ae6b69d7b0d1d1a059d9
sha512: 542f316dbd5376433f400da5b2d88fd156df1d1bf5d8d90e48d466b3ba356c7f7522b85850f854f4165ad17c2369e62a6821013e92a782fe227eb3a6e06b7c14
ssdeep: 12288:4QBCgCNsu9HxDsEscoH6nCAhG5co6a+4w//EeMMd9t7nxpTX:4YdCzxoEEyBG5GaU8zK9F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EKMF also known as:

MicroWorld-eScanTrojan.Agent.Delf.RXZ
FireEyeGeneric.mg.b881e19d5babbea0
Qihoo-360Win32/Trojan.469
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.Delf.RXZ
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.170734
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34090.RGW@au172bii
F-ProtW32/Injector.IVV
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R020H0CBB20
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Fareit.2312721f
AegisLabTrojan.Win32.Malicious.4!c
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.Agent.Delf.RXZ
SophosMal/Fareit-V
McAfee-GW-EditionBehavesLike.Win32.Fareit.jh
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Agent.Delf.RXZ (B)
SentinelOneDFI – Suspicious PE
WebrootW32.Trojan.Gen
MAXmalware (ai score=89)
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Win-Trojan/Delphiless.Exp
McAfeeFareit-FRB!B881E19D5BAB
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.EKMF
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_67%
FortinetW32/Agent.AJFK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.EKMF?

Win32/Injector.EKMF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment