Malware

Win32/Injector.EMID malicious file

Malware Removal

The Win32/Injector.EMID is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EMID virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Malayalam
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EMID?


File Info:

crc32: B49C4454
md5: a2a9af51271808f37748c7f31a4a999f
name: A2A9AF51271808F37748C7F31A4A999F.mlw
sha1: 10185029933c02f0b4906e7095154ea109b30241
sha256: 87bc4be707dcc8baa84f7c07543d464fc0da73b2be27bfbf814b179c05ebfbfb
sha512: 17d1c244c23c8cbf2d2a29065fa832e8c29e680ba9133a39922e48cb0f92ca898b7768e272bd0321db0a815ee4943445eaaccae91bdab4e56b326cac5621d145
ssdeep: 6144:vDhqe0E073Cwk2E6wm9bux+RpDtDtFl6RL72FNzny75rawv:v9v0E073Cw+6wqwyphTlSiNzy75rhv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Paul Bahlawan April 2003
InternalName: Hexsweeper
FileVersion: 1.00.0023
CompanyName: Minesweeper Inc.
ProductName: HexSweeper
ProductVersion: 1.00.0023
FileDescription: Minesweeper with its hexagonal tiles. Uses a subrutine recursively to clear out open areas and transperant BitBlt to draw the tiles
OriginalFilename: Hexsweeper.exe

Win32/Injector.EMID also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.43199
MicroWorld-eScanTrojan.GenericKDZ.67272
ALYacTrojan.GenericKDZ.67272
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKDZ.67272
K7GWTrojan ( 005669b91 )
K7AntiVirusTrojan ( 005677851 )
BitDefenderThetaGen:NN.ZevbaF.34590.Bm1@aO@r2HbO
CyrenW32/Trickbot.DY.gen!Eldorado
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan.Win32.Mansabo.evh
NANO-AntivirusTrojan.Win32.TrickBot.hkykgp
Ad-AwareTrojan.GenericKDZ.67272
SophosMal/Trickbot-I
ComodoTrojWare.Win32.TrickBot.ADF@8s4jlf
F-SecureHeuristic.HEUR/AGEN.1134711
ZillyaTrojan.Mansabo.Win32.1790
InvinceaML/PE-A + Mal/Trickbot-I
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
EmsisoftTrojan.GenericKDZ.67272 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Mansabo.bmu
MaxSecureTrojan.Malware.101639626.susgen
AviraHEUR/AGEN.1134711
Antiy-AVLTrojan/Win32.Mansabo
MicrosoftTrojan:Win32/Trickbot.DHN!MTB
ArcabitTrojan.Generic.D106C8
SUPERAntiSpywareTrojan.Agent/Gen-TrickBot
ZoneAlarmTrojan.Win32.Mansabo.evh
GDataTrojan.GenericKDZ.67272
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Trickbot.C4103580
McAfeeTrickbot-FSNZ!A2A9AF512718
MAXmalware (ai score=89)
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
ZonerTrojan.Win32.91375
ESET-NOD32a variant of Win32/Injector.EMID
TencentMalware.Win32.Gencirc.10cdcb3b
YandexTrojan.TrickBot!KgK63ceiz6w
IkarusTrojan.Win32.Injector
FortinetW32/TrickBot.DI!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM03.0.3967.Malware.Gen

How to remove Win32/Injector.EMID?

Win32/Injector.EMID removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment