Malware

What is “Win32/Injector.EKUM”?

Malware Removal

The Win32/Injector.EKUM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKUM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Win32/Injector.EKUM?


File Info:

crc32: 1E81D1C0
md5: 46479e966974d28232640ecc8081fcc5
name: drop.bin
sha1: 6fe626e782dd29fe5fb0211254865f07a1619623
sha256: fdc7887075348c904369719c79b49e6449d0cff9ece8c5e87879dd75872f20d6
sha512: 970fd6f364372da8045ac2b5774c6597dca43a23b92ec4935d1604e6dc390d8aa949ae4827be008a016959388f6b71e8435776f1735a7ca937ea0072c4e8e48e
ssdeep: 3072:Kfy+bnr+O1y5GWp1icKAArDZz4N9GhbkrNEk1bV/Ugo/:Kfy+bnr+Fp0yN90QEcV/W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Win32/Injector.EKUM also known as:

MicroWorld-eScanTrojan.GenericKD.42703659
McAfeeArtemis!46479E966974
CylanceUnsafe
AegisLabTrojan.Win32.Dorifel.b!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42703659
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.42703659
KasperskyHEUR:Trojan-Dropper.Win32.Dorifel.vho
RisingDropper.Dorifel!8.31E (CLOUD)
Ad-AwareTrojan.GenericKD.42703659
F-SecureTrojan.TR/Dropper.VB.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.dm
FireEyeGeneric.mg.46479e966974d282
EmsisoftTrojan.GenericKD.42703659 (B)
WebrootW32.Trojan.Gen
AviraTR/Dropper.VB.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28B9B2B
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dorifel.vho
MicrosoftTrojan:Win32/Occamy.C
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper.WXT.Generic
ESET-NOD32a variant of Win32/Injector.EKUM
TencentWin32.Trojan-dropper.Dorifel.Pbpf
IkarusTrojan-Spy.Agent
FortinetW32/Generik.EQCGIHG!tr
AVGFileRepMalware
Cybereasonmalicious.782dd2
Qihoo-360Win32/Trojan.Dropper.528

How to remove Win32/Injector.EKUM?

Win32/Injector.EKUM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment