Malware

Win32/Injector.ELH removal instruction

Malware Removal

The Win32/Injector.ELH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.ELH?


File Info:

crc32: 87186017
md5: deeda408c7dc87b711f1505e7e247ca3
name: DEEDA408C7DC87B711F1505E7E247CA3.mlw
sha1: fcc8385fcbea0ce3fadbdf3caef510f6da5f6e5a
sha256: f917598dfb3400a8de767455521b1812f26bf3d5786f1130e000154701d85d55
sha512: 8eaadc2167bd8bacc2df6886be75468e94e911e88c9ec691d7edfc8a8ba74310e1f3e17b97d140c3ece242f862ef26760e8b128859a2c3c859f88cd293c55213
ssdeep: 1536:UTNAkR9s+6sZMSY+A37feaCMJDmYsLIb4PvYqHB/AdGD:eB9szsZMSDADeak7dJHB/AdGD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Win32/Injector.ELH also known as:

BkavW32.InjectBPS.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Tofsee.Gen
FireEyeGeneric.mg.deeda408c7dc87b7
CAT-QuickHealTrojan.Bagsu.P4.mue
Qihoo-360Win32/Trojan.2fa
ALYacBackdoor.Tofsee.Gen
CylanceUnsafe
VIPRETrojan.Win32.Inject.cj (v)
SangforMalware
K7AntiVirusTrojan ( 002331771 )
BitDefenderBackdoor.Tofsee.Gen
K7GWTrojan ( 001fbdf71 )
Cybereasonmalicious.8c7dc8
BaiduWin32.Trojan.Inject.bf
CyrenW32/Injector.AV.gen!Eldorado
SymantecTrojan.Dropper
APEXMalicious
AvastWin32:Taidoor-D [Trj]
ClamAVWin.Trojan.Inject-132
KasperskyTrojan.Win32.Inject.bbyo
NANO-AntivirusTrojan.Win32.Inject.csnmkc
AegisLabTrojan.Win32.Inject.lJhA
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareBackdoor.Tofsee.Gen
SophosML/PE-A + Troj/CeeInj-M
ComodoTrojWare.Win32.Inject.ka@4o81ww
F-SecureMalware.W32/Almanahe.C
DrWebTrojan.DownLoad2.36100
ZillyaTrojan.InjectGen.Win32.5
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.kc
EmsisoftBackdoor.Tofsee.Gen (B)
IkarusBackdoor.Win32.Simbot
AviraW32/Almanahe.C
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Inject.bbyo
MicrosoftTrojan:Win32/Dorv.A
ArcabitBackdoor.Tofsee.Gen
SUPERAntiSpywareBackdoor.Bot/Variant
ZoneAlarmTrojan.Win32.Inject.bbyo
GDataBackdoor.Tofsee.Gen
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R7666
Acronissuspicious
McAfeeBackDoor-EYG
TACHYONTrojan/W32.Inject.66560.VV
VBA32SScope.Backdoor.Simbot
MalwarebytesSimbot.Backdoor.Stealer.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.ELH
TrendMicro-HouseCallTROJ_KRYPTK.SMS
TencentTrojan.Win32.Inject.bbyoa
YandexTrojan.GenAsa!5YxMY2U2QLk
SentinelOneStatic AI – Malicious PE – Spyware
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELH!tr
BitDefenderThetaAI:Packer.515AA8091F
AVGWin32:Taidoor-D [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.ELH?

Win32/Injector.ELH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment