Malware

About “Win32/Injector.ELIR” infection

Malware Removal

The Win32/Injector.ELIR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELIR virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Attempts to mimic the file extension of a JPG image by having ‘jpg’ in the file name.
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
Bestza.wshells.ws
a.tomx.xyz

How to determine Win32/Injector.ELIR?


File Info:

crc32: 5695C91A
md5: 2f649bc7d6eab98800f5f1d873df4c00
name: image00619_jpg.exe
sha1: 9b19344e604be27c0f549fdaa436c8163c1b56d8
sha256: 57b229af418a66936d7399369a169ef82e211c3d5817d96c0072b226b3716186
sha512: bf33921767d16b885445c2f61f74059b6aab818ec0cf14a6b51e262f934b4bd10f0f3c23e1bf94852c7d193bb9e45d344813c229683cee18db871ad12cc87459
ssdeep: 12288:lbZqJ+db/pbUwTDvtqU+VPWZhBDKF/OGEw3upDqbGJG1i4lm:F4IzofNENJLKugq7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.ELIR also known as:

MicroWorld-eScanTrojan.GenericKD.33608078
Qihoo-360Generic/HEUR/QVM05.1.52F7.Malware.Gen
McAfeeFareit-FRQ!2F649BC7D6EA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.IRCbot.4!c
SangforMalware
K7AntiVirusTrojan ( 005555ed1 )
BitDefenderTrojan.GenericKD.33608078
K7GWTrojan ( 005555ed1 )
Cybereasonmalicious.e604be
TrendMicroTrojanSpy.Win32.LOKI.SMDF.hp
F-ProtW32/Delf.AFP
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33608078
KasperskyHEUR:Trojan.Win32.IRCbot.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
ViRobotTrojan.Win32.Z.Injector.773120.B
RisingTrojan.Injector!1.AFE3 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33608078 (B)
DrWebTrojan.Siggen9.32898
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.bh
FireEyeGeneric.mg.2f649bc7d6eab988
SophosMal/Generic-S
CyrenW32/Delf.UBBF-7540
WebrootW32.Trojan.Gen
MAXmalware (ai score=89)
ArcabitTrojan.Generic.D200D18E
ZoneAlarmHEUR:Trojan.Win32.IRCbot.gen
MicrosoftTrojan:Win32/Lokibot.ART!MTB
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
VBA32Trojan.Lokibot
ALYacTrojan.GenericKD.33608078
Ad-AwareTrojan.GenericKD.33608078
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.ELIR
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMDF.hp
TencentWin32.Trojan.Ircbot.Htwe
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Injector.EESQ!tr
BitDefenderThetaGen:NN.ZelphiF.34104.VGW@aWad32ni
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.ELIR?

Win32/Injector.ELIR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment