Malware

Win32/Injector.ELBX malicious file

Malware Removal

The Win32/Injector.ELBX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELBX virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

uzoclouds.eu

How to determine Win32/Injector.ELBX?


File Info:

crc32: 61C2AF95
md5: 2ae37f6ed3787816365968e9b9983a0e
name: endyz.exe
sha1: 66f8c154ff0b19ecbcaacd677a07235504c1f266
sha256: 136c2f2bd1b90d0890cee4825c70de90e062da85699ef68bd394d9149eb9fbeb
sha512: 65a2900768c1baee36214fa2e2c225c1a8397f4773ee2f5cc863314737222800a9e96b59a4789e1e881ba0e85f62e6a9c4b1b6146302f5b2cb601cc07b49368a
ssdeep: 12288:HToUkEknbg77lbmW7TrKEuwf03VpIcgHur+BmWVJBSALgPD8P79MymYzF:HU+kmVmGvKEuA0LItXBdf8WgQPCyB5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.ELBX also known as:

MicroWorld-eScanTrojan.GenericKD.33549287
Qihoo-360HEUR/QVM05.1.F465.Malware.Gen
McAfeeArtemis!2AE37F6ED378
MalwarebytesSpyware.LokiBot
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33549287
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4ff0b1
TrendMicroTrojanSpy.Win32.LOKI.SMDF.hp
BitDefenderThetaGen:NN.ZelphiF.34100.TGW@ae4S@Jpi
CyrenW32/Injector.MNDS-6512
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ELBX
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMDF.hp
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
RisingTrojan.Injector!1.AFE3 (CLOUD)
Ad-AwareTrojan.GenericKD.33549287
EmsisoftTrojan.GenericKD.33549287 (B)
DrWebTrojan.Siggen9.21473
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.bh
FortinetW32/Injector.EDUW!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2ae37f6ed3787816
SophosMal/Fareit-V
APEXMalicious
F-ProtW32/Injector.IZV
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFEBE7
ZoneAlarmHEUR:Trojan-PSW.Win32.Agensla.gen
MicrosoftPWS:Win32/Stimilina.E!bit
Acronissuspicious
ALYacTrojan.GenericKD.42852869
CylanceUnsafe
PandaTrj/Genetic.gen
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_99%
GDataWin32.Trojan.Agent.AH9S4A
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.ELBX?

Win32/Injector.ELBX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment