Malware

What is “Win32/Injector.EMDU”?

Malware Removal

The Win32/Injector.EMDU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EMDU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EMDU?


File Info:

crc32: 415079C8
md5: 27b0a97953e33652be250639d6bbcf2a
name: vbc.exe
sha1: 8c0fed14d12ffcb1e90cc6f6507128dbf9826c99
sha256: 13e764a18e1a85dc72ef910f952c660d580da976412e36efedca52e65b5790f4
sha512: 0bde92776ec26ec7e94bbfe71281713ebb87be7403aec6fecfef2a113546cc8457f37881162dd5628105f0014274292c07ce4006e2a9fb2d7e30a3f1e9b7e990
ssdeep: 1536:wzo40YX8wLEt3W/5/I54+FBMhufjNOwVZ79u2lUk+CsaTAoL4:a1rnEt2kpFKhufjlVN9zb6oU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Slagbasser
FileVersion: 2.03
CompanyName: Ypsilon Vivers corporation
Comments: Ypsilon Vivers corporation
ProductName: SUPRACHO
ProductVersion: 2.03
OriginalFilename: Slagbasser.exe

Win32/Injector.EMDU also known as:

MicroWorld-eScanGen:Heur.PonyStealer.hm0@BWuj2Ibi
ALYacGen:Heur.PonyStealer.hm0@BWuj2Ibi
MalwarebytesTrojan.GuLoader
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderGen:Heur.PonyStealer.hm0@BWuj2Ibi
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.PonyStealer.E6A036
CyrenW32/VBKrypt.ALK.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EMDU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vebzenpak.tns
AlibabaTrojan:Win32/Vebzenpak.ec057435
Ad-AwareGen:Heur.PonyStealer.hm0@BWuj2Ibi
EmsisoftGen:Heur.PonyStealer.hm0@BWuj2Ibi (B)
F-SecureTrojan.TR/AD.VBCryptor.ebcnu
TrendMicroTROJ_FRS.0NA103ES20
McAfee-GW-EditionFareit-FTQ!27B0A97953E3
FortinetW32/Injector.EMDM!tr
FireEyeGen:Heur.PonyStealer.hm0@BWuj2Ibi
SophosMal/FareitVB-AE
F-ProtW32/VBKrypt.ALK.gen!Eldorado
WebrootW32.Malware.Gen
AviraTR/AD.VBCryptor.ebcnu
MAXmalware (ai score=88)
Endgamemalicious (high confidence)
MicrosoftPWS:Win32/Fareit.W!MTB
ZoneAlarmTrojan.Win32.Vebzenpak.tns
McAfeeFareit-FST!27B0A97953E3
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103ES20
RisingDownloader.Guloader!1.C6E5 (CLOUD)
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_69%
GDataGen:Heur.PonyStealer.hm0@BWuj2Ibi
BitDefenderThetaGen:NN.ZevbaCO.34122.hm0@aWuj2Ibi
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.468

How to remove Win32/Injector.EMDU?

Win32/Injector.EMDU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment