Malware

How to remove “Win32/Injector.ELDF”?

Malware Removal

The Win32/Injector.ELDF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELDF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.ELDF?


File Info:

crc32: 87B6408F
md5: d99f5de40fc0a4dc5f0ba27cbd13b821
name: zyn.exe
sha1: 37c756f6b5fe202bcba62243fbea68d42d673258
sha256: 0fa06a52c29349ba1af4382e94f7cadcc1aa10d0b82737bf7fa9f0374971dc9a
sha512: fc6f4d838c791ac933be5acd50e166d13b852a5ab03f19cc0f4bcba7fd4382fba5bc9cd2a738761a55d23c5a1a95379ebd7e0c0990772957ec817474e838f940
ssdeep: 1536:jo4pICU2RQx48mTUhpMqZRDS1MADUcFu43gxh6aX:1IuQx4ZOe9JuAq6o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Ophiopluteusst2
FileVersion: 1.00
CompanyName: ubisOFT
Comments: ubisOFT
ProductName: VALIDTB
ProductVersion: 1.00
FileDescription: Palatalize9
OriginalFilename: Ophiopluteusst2.exe

Win32/Injector.ELDF also known as:

MicroWorld-eScanTrojan.GenericKD.33555448
McAfeeArtemis!D99F5DE40FC0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Remcos.m!c
SangforMalware
K7AntiVirusTrojan ( 00562ec31 )
BitDefenderTrojan.GenericKD.33555448
K7GWTrojan ( 00562ec31 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTROJ_GEN.R002C0PCK20
F-ProtW32/Injector.AAM.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.33555448
KasperskyBackdoor.Win32.Remcos.nob
AlibabaBackdoor:Win32/Remcos.e279b23a
ViRobotTrojan.Win32.Z.Injector.114688.WQ
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Remcos.Wtdv
Ad-AwareTrojan.GenericKD.33555448
SophosMal/FareitVB-W
F-SecureTrojan.TR/Injector.gjedj
DrWebTrojan.PWS.Siggen2.45154
McAfee-GW-EditionFareit-FRL!D99F5DE40FC0
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.33555448 (B)
IkarusTrojan.Win32.Injector
CyrenW32/Injector.AAM.gen!Eldorado
WebrootW32.Injector.Gen
AviraTR/Injector.gjedj
eGambitUnsafe.AI_Score_72%
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D20003F8
ZoneAlarmBackdoor.Win32.Remcos.nob
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.VBKrypt.R329114
ALYacTrojan.GenericKD.33555448
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.VB
ESET-NOD32a variant of Win32/Injector.ELDF
TrendMicro-HouseCallTROJ_GEN.R002C0PCK20
RisingBackdoor.Remcos!8.B89E (CLOUD)
FortinetW32/Injector.ELDR!tr
BitDefenderThetaGen:NN.ZevbaF.34100.hm0@aqqZ9Fni
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
Qihoo-360Win32/Backdoor.d9d

How to remove Win32/Injector.ELDF?

Win32/Injector.ELDF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment