Malware

What is “Win32/Injector.ELGG”?

Malware Removal

The Win32/Injector.ELGG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELGG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.fetesdevillage.com
www.facehack.tech
www.verybull.com

How to determine Win32/Injector.ELGG?


File Info:

crc32: 4D89627A
md5: 8dacccc71d7e301368047e02e5c0d8ad
name: mic.exe
sha1: a0a1bcdc7de3981dc9a551d37a1d7edf9df2a027
sha256: afb4393cb23ab356cdac8d5cd85ec37a371af478fa03ce653d70f3ad371b8603
sha512: 9c9f0f8ff453028184f7483a91d03e27183602d0a3a503112b5b89a82c846a2226e01a684292c574d8b8a413bbc1b163ca182431b40b1b8db24e0f620da4cce3
ssdeep: 12288:W9cW1pusQR7tkglIYH0EhBWqnH5fN+WCrzrYuCRR:WlZOtkkB08D58WCgRR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.ELGG also known as:

Qihoo-360HEUR/QVM05.1.2939.Malware.Gen
BitDefenderThetaGen:NN.ZelphiF.34104.TGX@aWU@4Aci
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
Invinceaheuristic
F-ProtW32/Delf.AFI
ESET-NOD32a variant of Win32/Injector.ELGG
APEXMalicious
KasperskyHEUR:Trojan.Win32.Kryptik.gen
Endgamemalicious (high confidence)
TrendMicroTrojanSpy.Win32.LOKI.SMDF.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8dacccc71d7e3013
SophosMal/Fareit-V
CyrenW32/Delf.ZLQS-3748
JiangminTrojan.PSW.Chisburg.bgl
MicrosoftTrojanSpy:Win32/Swotter.A!bit
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
CylanceUnsafe
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMDF.hp
RisingTrojan.Injector!1.AF18 (CLASSIC)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELFW!tr
Cybereasonmalicious.c7de39
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.ELGG?

Win32/Injector.ELGG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment