Malware

What is “Win32/Injector.EMLX”?

Malware Removal

The Win32/Injector.EMLX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EMLX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EMLX?


File Info:

crc32: 579CE430
md5: 28bfa36c14b71749e57c3e53d4369e1e
name: 28BFA36C14B71749E57C3E53D4369E1E.mlw
sha1: 748dbf5b494652baf7c3b7dd249fb72bc7d62d4b
sha256: ce77e7c22cd0ffc5f494180077ae9522a7dc6a0879a47826b6257865a6ceb74f
sha512: f5c413412cbd0eff243270f3e592e774caacf13267ef93e5fc3c80c533c04178e8bde8d13be6970ad50170788e622ce408a2874400802bae21e3b64bf5c459ca
ssdeep: 6144:xPVJESx72mkaQVUUpgLPrOQfylHPwYpd8pJXWZqvuV14UKQ0Xae8mzSZ/gYw036a:x1ogB5ylHPGeXKQ8a3muZ/gYoBWo3m
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Graph
FileVersion: 1.00
CompanyName: Xansa
Comments: By Rajneesh Noonia
ProductName: Flow Chart Designer
ProductVersion: 1.00
OriginalFilename: Graph.exe

Win32/Injector.EMLX also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.256973
FireEyeGeneric.mg.28bfa36c14b71749
ALYacGen:Variant.Johnnie.256973
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Johnnie.256973
CyrenW32/VBInject.AEH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan.Win32.Bsymem.rim
RisingTrojan.Injector!8.C4 (TFE:4:KGTpqvhHo9C)
Ad-AwareGen:Variant.Johnnie.256973
TACHYONTrojan/W32.VB-Bsymem.638976
EmsisoftGen:Variant.Johnnie.256973 (B)
F-SecureHeuristic.HEUR/AGEN.1134970
DrWebTrojan.Packed.140
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Trickbot.jh
JiangminTrojan.Bsymem.aav
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1134970
Antiy-AVLTrojan/Win32.Bsymem
MicrosoftTrojan:Win32/Bsymem.DEC!MTB
ArcabitTrojan.Johnnie.D3EBCD
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
ZoneAlarmTrojan.Win32.Bsymem.rim
GDataGen:Variant.Johnnie.256973
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R342942
McAfeeTrickbot-FSNZ!28BFA36C14B7
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EMLX
YandexTrojan.Injector!fRmMkEBU93A
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.102778529.susgen
FortinetW32/Injector.EMLX!tr
BitDefenderThetaGen:NN.ZevbaF.34634.Nm0@aG0!dIcO
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Win32/Injector.EMLX?

Win32/Injector.EMLX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment