Malware

Win32/Injector.EKRF removal guide

Malware Removal

The Win32/Injector.EKRF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKRF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

us-east.randomx-hub.miningpoolhub.com

How to determine Win32/Injector.EKRF?


File Info:

crc32: 6FDF6D1B
md5: d178b0dbe660bae78612a9cb1b75650c
name: file3.exe
sha1: e6d5ba505a7dd2940e3c4aeb82c3710eeddf272e
sha256: 7ba215a518d9b02dab18199f21db1b2988f3c1dd97a3c56dfbbfa322bcfd26d4
sha512: d2c5358304066e11e8a2f85d54c5138870f57fa7943eb33175644c5a81a6aea967c00dbe0c4189e0abe591d5102dbed3b6478e70e4a07a8b56d325f50ff43298
ssdeep: 49152:WtkUNIPSdHklnOCkOttbwhWYDMVaE6AaANW7uCSHHi/y:WtkyHkZkOgVMVoDSHP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EKRF also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.PWS.AgenslaNET.1
MicroWorld-eScanTrojan.GenericKD.33362555
FireEyeGeneric.mg.d178b0dbe660bae7
Qihoo-360Generic/Trojan.7b8
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005610661 )
BitDefenderTrojan.GenericKD.33362555
K7GWTrojan ( 005610661 )
Cybereasonmalicious.05a7dd
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34090.nIW@aK48hGoi
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33362555
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Lokibot.2a73e8cb
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.33362555
SophosMal/Fareit-V
F-SecureTrojan.TR/Crypt.Agent.zoqzg
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DBM20
McAfee-GW-EditionBehavesLike.Win32.Fareit.vc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33362555 (B)
SentinelOneDFI – Suspicious PE
AviraTR/Crypt.Agent.zoqzg
Antiy-AVLTrojan/Win32.Lokibot
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FD127B
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Lokibot.ART!MTB
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
McAfeeFareit-FRB!D178B0DBE660
MAXmalware (ai score=83)
MalwarebytesTrojan.Injector
ESET-NOD32a variant of Win32/Injector.EKRF
TrendMicro-HouseCallTROJ_GEN.R002C0DBM20
RisingTrojan.Lokibot!8.F1B5 (TFE:5:brZe9ieToWQ)
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_96%
FortinetW32/Agent.AJFK!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.EKRF?

Win32/Injector.EKRF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment