Malware

Win32/Injector.EKPA removal guide

Malware Removal

The Win32/Injector.EKPA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKPA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EKPA?


File Info:

crc32: EA0E08B5
md5: e376a8f32bd6c0be39eba3d6e9edfe21
name: invoicerequest.exe
sha1: a28a091548cf27a98286741655738747cae8d724
sha256: a1311b348005d922c27a30258236ad7ab19a5d9e029031f105b700003b7ab4f6
sha512: d6937824cbf97574c38c47b3442aa306f2a0d18d6322de48a5b66363ab4bfa2f9126b85eab00aba88a79981704cd9a4309d60ce5e09f8aa194552931fdf07217
ssdeep: 24576:q1eOmnieUocHujc4HF+xDBPlewg1dVp6SaOeppm1WRTP9+UmGaZFzz:WgiecOjc4YPXg1dRSC1WRL93FaZxz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EKPA also known as:

DrWebTrojan.PWS.AgenslaNET.1
MicroWorld-eScanTrojan.GenericKD.33293174
FireEyeGeneric.mg.e376a8f32bd6c0be
McAfeeFareit-FRB!E376A8F32BD6
MalwarebytesSpyware.LokiBot
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.33293174
K7GWTrojan ( 00560ba91 )
K7AntiVirusTrojan ( 00560ba91 )
TrendMicroTROJ_FRS.VSNTBI20
BitDefenderThetaGen:NN.ZelphiF.34090.xHW@amkZsHhi
F-ProtW32/Injector.IXF
SymantecTrojan Horse
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.33293174
KasperskyHEUR:Backdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/Androm.5c8cb6ff
NANO-AntivirusTrojan.Win32.AgenslaNET.hbdgpr
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33293174 (B)
F-SecureTrojan.TR/Dropper.bhmgx
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
Trapminemalicious.moderate.ml.score
SophosMal/Fareit-V
CyrenW32/Injector.HOGM-5022
WebrootW32.Trojan.Gen
AviraTR/Dropper.bhmgx
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Win32.Fuerboos
MicrosoftTrojan:Win32/Lokibot.ART!eml
ArcabitTrojan.Generic.D1FC0376
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
ALYacTrojan.GenericKD.33293174
MAXmalware (ai score=86)
VBA32TScope.Trojan.Delf
CylanceUnsafe
PandaTrj/CI.A
ZonerTrojan.Win32.71847
ESET-NOD32a variant of Win32/Injector.EKPA
TrendMicro-HouseCallTROJ_FRS.VSNTBI20
RisingTrojan.Injector!1.AFE3 (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.AJFK!tr
Ad-AwareTrojan.GenericKD.33293174
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.548cf2
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.650

How to remove Win32/Injector.EKPA?

Win32/Injector.EKPA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment