Malware

Should I remove “Win32/Injector.ELXQ”?

Malware Removal

The Win32/Injector.ELXQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ELXQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.ELXQ?


File Info:

crc32: 7E81833B
md5: 15e2319b52446df95d9e487209999679
name: ap.jpeg
sha1: 01d3c2c0118a03e456ee1b27aeffc07efb8f88bf
sha256: 3d4dedbfa652e77ab616c509f6fcf16b0ebcead701096742af5e9fe8e9413aa3
sha512: 9905204adae25b3e84a4c4459764f3784329e710da2fabdb2c37d4fa3fc362dea6780693b54a97100699547ba53968a5c6f616f061ca69cca6e7bc0aedf5c7c4
ssdeep: 768:hhd+4ovEYaFbRGBvd+rkd79iiqgJCNsBvTsoBYhH0r+A6JawOGjlmds9jF5vh/:nzxYaEw6qgJCWBtdkLjB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Spigretfl6
FileVersion: 2.09
CompanyName: NOodles
ProductName: fejl
ProductVersion: 2.09
OriginalFilename: Spigretfl6.exe

Win32/Injector.ELXQ also known as:

MicroWorld-eScanGen:Heur.PonyStealer.fm0@BSAle7ei
FireEyeGen:Variant.Ser.Ursu.20025
McAfeeFareit-FTA!15E2319B5244
MalwarebytesTrojan.GuLoader.VB
K7AntiVirusTrojan ( 005669fc1 )
BitDefenderGen:Heur.PonyStealer.fm0@BSAle7ei
K7GWTrojan ( 005669fc1 )
TrendMicroTrojan.Win32.WACATAC.THEAEBO
F-ProtW32/VBKrypt.AKP.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Generic-7788440-0
GDataGen:Heur.PonyStealer.fm0@BSAle7ei
KasperskyTrojan.Win32.Vebzenpak.pww
AlibabaTrojan:Win32/Vebzenpak.b03ebf71
AegisLabTrojan.Win32.Vebzenpak.4!c
TencentWin32.Trojan.Vebzenpak.Eadu
Endgamemalicious (high confidence)
SophosMal/FareitVB-AB
ComodoMalware@#14iugkdcy84xy
F-SecureTrojan.TR/Injector.jiocv
DrWebTrojan.Siggen9.46112
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.mz
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.PonyStealer.fm0@BSAle7ei (B)
IkarusTrojan.VB.Crypt
CyrenW32/VBKrypt.AKP.gen!Eldorado
AviraTR/Injector.jiocv
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Vebzenpak
ArcabitTrojan.PonyStealer.EC6F6A
ZoneAlarmTrojan.Win32.Vebzenpak.pww
MicrosoftTrojan:Win32/PonyStealer.PE!MTB
AhnLab-V3Trojan/Win32.VBKrypt.R336399
ALYacGen:Heur.PonyStealer.fm0@BSAle7ei
Ad-AwareGen:Heur.PonyStealer.fm0@BSAle7ei
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELXQ
TrendMicro-HouseCallTROJ_GEN.R002C0WED20
RisingTrojan.Injector!1.C624 (CLOUD)
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELXM!tr
BitDefenderThetaGen:NN.ZevbaCO.34110.fm0@aSAle7ei
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.9ff

How to remove Win32/Injector.ELXQ?

Win32/Injector.ELXQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment