Malware

Win32/Injector.ELHM removal instruction

Malware Removal

The Win32/Injector.ELHM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELHM virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

hillbiz.top

How to determine Win32/Injector.ELHM?


File Info:

crc32: 9C4E283C
md5: 64735c74cd934aaf19aba648c27ce4cd
name: anyisouthz.exe
sha1: 93e73fe62e340d10eb79991ab82bafee43f4ae9c
sha256: 3208ba3315a6bb28229a69bd98ba5484ab596785d8b5fb1e61b23c33fcd5664d
sha512: 093b6aed38436c4b7f3e24be9f7120a024723abd73f8327e78912afe53c3ff91a3e767f0d3f7651d1bfac6a167e231644ebdbb920fd222fe0689831e6c4fc3b1
ssdeep: 12288:wTzL3PK7n2KE9VtGQwZj1U8r56mo73LPPk1eDDuPxZxWsKxT1pR2UUe2byr5:MTPsn0ZDwZeEIv3I1afsK37281
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.ELHM also known as:

DrWebTrojan.DownLoader33.24437
Qihoo-360HEUR/QVM05.1.3F65.Malware.Gen
CylanceUnsafe
K7AntiVirusSpyware ( 0054b83d1 )
K7GWSpyware ( 0054b83d1 )
CrowdStrikewin/malicious_confidence_100% (D)
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34104.2GW@aeU35eei
F-ProtW32/Trojan2.QBTE
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Androm.gen
TrendMicroTrojanSpy.Win32.LOKI.SMDF.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.64735c74cd934aaf
CyrenW32/Trojan.RTDW-6944
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
ESET-NOD32a variant of Win32/Injector.ELHM
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMDF.hp
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazpmsvrP8ArSBXHmfipnnmYJ)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Injector.ELFW!tr
Cybereasonmalicious.62e340
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.ELHM?

Win32/Injector.ELHM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment