Malware

What is “Win32/Injector.EKZI”?

Malware Removal

The Win32/Injector.EKZI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EKZI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EKZI?


File Info:

crc32: 724173E8
md5: c09301e30e29a4ca527cfae39f5f34c2
name: ds.exe
sha1: 06e70fd77d6798e0a41c68cb80f2f0305c951d24
sha256: 531aeef0b8519a8fd6d6a3cfba64b50582f2afe487d321e5999758f0a1a454a9
sha512: ff054994fdbc80e1468896ea6475a8b1341f95466365530990f83f851ffa098e5d7ec2e1b31b15b209ef72f0e0b87fc76621dba8346060e10dd91cecb4f380f6
ssdeep: 768:uiaBfk1ezDY41JtxchhvA1d8XRKb2xiM4lR:EB6hyP8XRn2lR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: unpalatal
FileVersion: 1.00
CompanyName: Vodafone
ProductName: Stemwares8
ProductVersion: 1.00
FileDescription: Sminkekr4
OriginalFilename: unpalatal.exe

Win32/Injector.EKZI also known as:

MicroWorld-eScanTrojan.GenericKD.33531812
McAfeeArtemis!C09301E30E29
CylanceUnsafe
AegisLabTrojan.Win32.Vebzenpak.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33531812
K7GWRiskware ( 0040eff71 )
F-ProtW32/Injector.AAE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33531812
KasperskyTrojan.Win32.Vebzenpak.gqc
AlibabaTrojan:Win32/vbcrypt.ali2000008
TencentWin32.Trojan.Vebzenpak.Swud
Ad-AwareTrojan.GenericKD.33531812
EmsisoftTrojan.GenericKD.33531812 (B)
F-SecureTrojan.TR/Injector.uieri
DrWebTrojan.PWS.Siggen2.44634
McAfee-GW-EditionBehavesLike.Win32.BadFile.kt
Trapminemalicious.high.ml.score
SophosMal/FareitVB-W
IkarusTrojan-Spy.Keylogger.AgentTesla
CyrenW32/Injector.AAE.gen!Eldorado
AviraTR/Injector.uieri
eGambitUnsafe.AI_Score_95%
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFA7A4
ZoneAlarmTrojan.Win32.Vebzenpak.gqc
MicrosoftTrojan:Win32/Dynamer!rfn
AhnLab-V3Trojan/Win32.VBKrypt.R328182
ALYacGen:Heur.PonyStealer.dm0@pmALXxki
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKZI
RisingTrojan.Vebzenpak!8.11687 (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetW32/GuLoader.VHHM!tr
BitDefenderThetaGen:NN.ZevbaCO.34100.dm0@amALXxki
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.63b

How to remove Win32/Injector.EKZI?

Win32/Injector.EKZI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment