Malware

About “Win32/Injector.EKSJ” infection

Malware Removal

The Win32/Injector.EKSJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKSJ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Portuguese
  • The binary likely contains encrypted or compressed data.
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.EKSJ?


File Info:

crc32: C2A4B3F5
md5: c7244bd0b92225c0b8f9ab5f6d9aad8b
name: redcar.png
sha1: 422b0d951753a68efbeae1b954377ece9fec2104
sha256: 1812c2632e0ba81fbd2c712f87e72878feacf11babe50662c081b943a3c34257
sha512: 2a8664b8fe013a78f972764787fdad04ba21d253f42ecca49defaade912d9e082c97efc5a3c6cbe03f7a12f7b7f6683b7017a24e076c44e652fe5d3d402f55b7
ssdeep: 12288:tzzk6BcVUmIDzzOeIIAQk2fp7khhFzi1u5WCSE:tzztvmIzOFIA2ehFmo5uE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: FPDD
FileVersion: 1.0.0.0
CompanyName: VorteX
ProductName: FPDD
ProductVersion: 1.0.0.0
FileDescription: I was planning for more but never had time
OriginalFilename: FPDD.exe

Win32/Injector.EKSJ also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Trick.46524
MicroWorld-eScanTrojan.Agent.EMNS
FireEyeGeneric.mg.c7244bd0b92225c0
Qihoo-360Generic/Trojan.4e2
McAfeeRDN/Generic.hbg
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Vebzenpak.4!c
SangforMalware
K7AntiVirusTrojan ( 005615af1 )
BitDefenderTrojan.Agent.EMNS
K7GWTrojan ( 005615af1 )
Cybereasonmalicious.51753a
TrendMicroTROJ_GEN.R011C0DBS20
BitDefenderThetaGen:NN.ZevbaF.34096.Gm0@aaWR63jO
CyrenW32/Kryptik.BEJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.Agent.EMNS
KasperskyTrojan.Win32.Vebzenpak.eee
AlibabaTrojan:Win32/Vebzenpak.b22fe431
NANO-AntivirusTrojan.Win32.Vebzenpak.hchvqx
ViRobotTrojan.Win32.Z.Genkryptik.532480.A
TencentMalware.Win32.Gencirc.10b8f51b
Ad-AwareTrojan.Agent.EMNS
SophosMal/Generic-S
F-SecureTrojan.TR/AD.TrickBot.byns
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Injector (A)
IkarusTrojan.Win32.Injector
F-ProtW32/Kryptik.BEJ.gen!Eldorado
JiangminTrojan.Vebzenpak.aiy
WebrootTrojan.Spy.Trickbot
AviraTR/AD.TrickBot.byns
Antiy-AVLTrojan/Win32.GenKryptik
Endgamemalicious (high confidence)
ArcabitTrojan.Agent.EMNS
ZoneAlarmTrojan.Win32.Vebzenpak.eee
MicrosoftTrojan:Win32/TrickBot.ARJ!MTB
TACHYONTrojan/W32.VB-Vebzenpak.532480
AhnLab-V3Trojan/Win32.Injector.R327518
ALYacTrojan.Agent.EMNS
MAXmalware (ai score=86)
MalwarebytesTrojan.TrickBot
PandaTrj/TrickBot.A
ESET-NOD32a variant of Win32/Injector.EKSJ
TrendMicro-HouseCallTROJ_GEN.R011C0DBS20
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneDFI – Malicious PE
FortinetW32/GenKryptik.EFFN!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.EKSJ?

Win32/Injector.EKSJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment