Malware

Should I remove “Win32/Injector.EKPP”?

Malware Removal

The Win32/Injector.EKPP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKPP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EKPP?


File Info:

crc32: FAD8ABC6
md5: ad80398cd5101c03d6fca25f783eaa29
name: elpatron6.exe
sha1: 3dee7d65da1c75b8e02187733b4acb4855bf38c3
sha256: 88b9a90aab00eebe48f48ed70229036b14cd6cd2deeeb38ccdaee9583b1d7f26
sha512: f9e29d6c869f9afe136cdc8f4b05e670ce7014efea34a2c71a17e869bed004f90096c8c88289e92c99aafede540ffb85df7fc182eed8fd0a70adf69e66abe570
ssdeep: 768:K+2F6L1zBmzpc+DXlUB3tSgGKUCT4abfHrMh6xvcQSr:K+2G1LptnG0kcvVZW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: stereosp
FileVersion: 1.00
CompanyName: Afblndenat1
Comments: Synodbrill5
ProductName: Fujits
ProductVersion: 1.00
FileDescription: Scenogr4
OriginalFilename: stereosp.exe

Win32/Injector.EKPP also known as:

MicroWorld-eScanTrojan.GenericKD.42602553
FireEyeTrojan.GenericKD.42602553
McAfeeFareit-FRM!AD80398CD510
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.42602553
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R011C0PBK20
F-ProtW32/Kryptik.BCI.gen!Eldorado
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Generic-7591178-0
GDataTrojan.GenericKD.42602553
KasperskyTrojan-Spy.Win32.Noon.auzr
AlibabaTrojan:Win32/Injector.0d187952
NANO-AntivirusTrojan.Win32.Noon.hbeqwy
AegisLabTrojan.Multi.Generic.4!c
RisingSpyware.Noon!8.E7C9 (CLOUD)
Ad-AwareTrojan.GenericKD.42602553
SophosMal/FareitVB-W
DrWebTrojan.PackedENT.133
McAfee-GW-EditionFareit-FRM!AD80398CD510
EmsisoftTrojan.GenericKD.42602553 (B)
IkarusTrojan.VB.Crypt
CyrenW32/Kryptik.BCI.gen!Eldorado
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28A1039
ZoneAlarmTrojan-Spy.Win32.Noon.auzr
MicrosoftTrojan:Win32/VBKrypt.AE!MTB
ALYacTrojan.Agent.Wacatac
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKPP
TrendMicro-HouseCallTROJ_GEN.R011C0PBK20
TencentWin32.Trojan-spy.Noon.Lpky
eGambitUnsafe.AI_Score_99%
FortinetW32/EKPP.W!tr
BitDefenderThetaGen:NN.ZevbaF.34090.dm0@aer8R1ii
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Trojan.Generic

How to remove Win32/Injector.EKPP?

Win32/Injector.EKPP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment