Malware

About “Win32/Injector.ELWO” infection

Malware Removal

The Win32/Injector.ELWO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELWO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.ELWO?


File Info:

crc32: 6B8976CF
md5: b504483582cdf83163ddba3b4fdffa98
name: e-checks-2020.29550-pdf.exe
sha1: 77d7a458be7b06d439e691d16da8d9f446a734ac
sha256: 6744646f70c4492939c7e66ff1296dc4ed4cb237652a0447d8c396ed8bedfdaa
sha512: 32945dae8db1c665fb1857f359507fb51f8e98bc56ed006638841431c0e561eab6a24bb1fa4a7a3d84165bd0f7052ebba11a6efb8a67ae771d51e0d69d91d6ca
ssdeep: 1536:wARGOo4jM9Wx4COythLgquv+wcjlvuc3Oq8GwX:8Oo4jMQaJyt/Qe9q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: Orchioneuralgia7
FileVersion: 1.05
CompanyName: TONELESSLY
Comments: Savskreres
ProductName: Project1
ProductVersion: 1.05
OriginalFilename: Orchioneuralgia7.exe

Win32/Injector.ELWO also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.43135653
McAfeeArtemis!B504483582CD
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.43135653
K7GWTrojan ( 00566a721 )
TrendMicroTrojan.Win32.WACATAC.THEAOBO
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.43135653
KasperskyTrojan.Win32.Vebzenpak.nyd
AlibabaTrojan:Win32/Vebzenpak.db078edd
AegisLabTrojan.Win32.Vebzenpak.4!c
TencentWin32.Trojan.Vebzenpak.Pcie
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43135653 (B)
ComodoMalware@#36t3kmww49exl
F-SecureTrojan.TR/RedCap.uchfs
McAfee-GW-EditionBehavesLike.Win32.AAEH.lm
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
JiangminTrojan.Vebzenpak.cls
AviraTR/RedCap.uchfs
eGambitUnsafe.AI_Score_77%
Antiy-AVLTrojan/Win32.Vebzenpak
MicrosoftTrojan:Win32/Dynamer!rfn
ArcabitTrojan.Generic.D29232A5
ZoneAlarmTrojan.Win32.Vebzenpak.nyd
BitDefenderThetaGen:NN.ZevbaF.34108.em0@aOck0jdb
ALYacTrojan.GenericKD.43135653
MAXmalware (ai score=85)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELWO
TrendMicro-HouseCallTrojan.Win32.WACATAC.THEAOBO
RisingBackdoor.Remcos!8.B89E (TFE:dGZlOgWqYoKrJbQKpQ)
FortinetW32/Vebzenpak.NYD!tr
Ad-AwareTrojan.GenericKD.43135653
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.4ec

How to remove Win32/Injector.ELWO?

Win32/Injector.ELWO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment