Malware

Win32/Injector.EKVV removal guide

Malware Removal

The Win32/Injector.EKVV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKVV virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EKVV?


File Info:

crc32: B672A5B6
md5: 65d9abb83f0169f190a6ee856349e447
name: originboby.exe
sha1: 8cf4af76cb75cbf7f5a2bac9eb5e1983de776241
sha256: 9f784cfff9b7cbdf40fe3bc0d0d864330be6df171c140533e9c727ca5bf7f441
sha512: 7480586943b78919f7357470a6fd12aa327ce27c4be361bf48598cc9bd085c129622dea5a81b6723191c80101deb5b043acd4242558544d9f195088595fe77df
ssdeep: 24576:zmlae/rd+Br9CvroYDmiOWJu7UkgriShKlDdd7c31:ylpUJ9qoYDmiOW07Dfc31
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EKVV also known as:

MicroWorld-eScanTrojan.GenericKD.42812314
McAfeeRDN/Generic.hbg
MalwarebytesTrojan.MalPack.DLF
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42812314
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6cb75c
ArcabitTrojan.Generic.D28D439A
TrendMicroTROJ_GEN.R002C0PC520
CyrenW32/Trojan.WNQC-0158
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.EKVV
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/Androm.b5e484ee
AvastWin32:Malware-gen
TencentWin32.Backdoor.Androm.Wqnh
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42812314 (B)
ComodoMalware@#3w2xuhl8crneq
DrWebTrojan.PWS.Siggen2.44295
MaxSecureTrojan.Malware.300983.susgen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
FortinetW32/Injector.EESQ!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.65d9abb83f0169f1
SophosMal/Generic-S
IkarusTrojan.Inject
F-ProtW32/Trojan3.AOYF
WebrootW32.Trojan.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
MicrosoftPWS:Win32/Fareit.AKK!MTB
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacTrojan.GenericKD.42812314
Ad-AwareTrojan.GenericKD.42812314
TrendMicro-HouseCallTROJ_GEN.R002C0PC520
RisingBackdoor.Androm!8.113 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.42812314
BitDefenderThetaGen:NN.ZelphiF.34098.!GW@aORG8hai
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM05.1.B419.Malware.Gen

How to remove Win32/Injector.EKVV?

Win32/Injector.EKVV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment