Malware

Win32/Injector.EKOS malicious file

Malware Removal

The Win32/Injector.EKOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKOS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EKOS?


File Info:

crc32: 6D5B2020
md5: 545b69c1913a9624e7605293ad76746a
name: a.exe
sha1: 1d29477d91e866ac27c04c78d6a49b74ccbe405e
sha256: f335f3849d8e49742ded741ad7098c7aee048916f137c63f0b5a446b1e18f031
sha512: 7d8f9cf3f3020d76bbaa0acc18843be9a66d5b8c66c1b3a7bd5f1576cd9aaa9b52cc1d8a548e1b56071a357380b6f4ee5abc7dcdbf0b7875565b9f4c93970c08
ssdeep: 768:60vmqYLnlxqQyLBe4XqkeSUWvcFJTM8/:5YDODLBe4XqkCWaog
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: INDUCE
FileVersion: 1.00
CompanyName: BIZCACHA
Comments: Superpiety2
ProductName: Overfati
ProductVersion: 1.00
FileDescription: Judiciou
OriginalFilename: INDUCE.exe

Win32/Injector.EKOS also known as:

DrWebTrojan.DownLoader33.3107
MicroWorld-eScanTrojan.GenericKD.33288025
FireEyeTrojan.GenericKD.33288025
McAfeeFareit-FRM!545B69C1913A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33288025
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZevbaF.34090.dm0@a8abFOjb
APEXMalicious
AvastWin32:Trojan-gen
GDataWin32.Trojan.Injector.NF8NAE
KasperskyTrojan.Win32.Vebzenpak.dcr
NANO-AntivirusTrojan.Win32.Dwn.hbbdhi
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Ad-AwareTrojan.GenericKD.33288025
EmsisoftTrojan.GenericKD.33288025 (B)
F-SecureHeuristic.HEUR/AGEN.1005598
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.qt
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
AviraHEUR/AGEN.1005598
ArcabitTrojan.Generic.D1FBEF59
ZoneAlarmTrojan.Win32.Vebzenpak.dcr
MicrosoftTrojan:Win32/Wacatac.C!ml
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.VB.Generic
ESET-NOD32a variant of Win32/Injector.EKOS
TencentWin32.Trojan.Vebzenpak.Sued
eGambitUnsafe.AI_Score_98%
FortinetW32/Injector.EKON!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Injector.EKOS?

Win32/Injector.EKOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment