Malware

Should I remove “Win32/Injector.EMNI”?

Malware Removal

The Win32/Injector.EMNI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EMNI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Malay (Brunei Darussalam)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/Injector.EMNI?


File Info:

crc32: 070954E9
md5: ffaa15b3361eca9712a4773416263696
name: FFAA15B3361ECA9712A4773416263696.mlw
sha1: 1cb6789c794788d10332aff1f6663f01ea63f076
sha256: 7b3d387ebac09fb507d28ee948cc637ea357f17a52eb2bf9afbe8efc69c411bf
sha512: 2b394be0b7631320704f8415e3ddb8507d5bfcf8bf14bbf646008208885f5dce951859c19d8e10c563482ae154c14f0dc667151fffd9685bd4d514846663670a
ssdeep: 6144:ArDOjkh+QMpVNNZNtu1aSkS33uE6kkTB7pYy:Afkkh+QMbTtoaNS3efkkTB1P
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Tous droits rx439servx439s par C.Dutoit
InternalName: GMindmapv03
FileVersion: 0.3.0.69
CompanyName: CORROSION
Comments: G-MindMap : Logiciel de crx439ation de Mindmaps
ProductName: G-Mindmap
ProductVersion: 0.3.0.69
FileDescription: G-MindMap
OriginalFilename: GMindmapv03.exe

Win32/Injector.EMNI also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.59985
MicroWorld-eScanTrojan.GenericKDZ.68293
FireEyeGeneric.mg.ffaa15b3361eca97
McAfeeTrickbot-FSNZ!FFAA15B3361E
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00569c651 )
BitDefenderTrojan.GenericKDZ.68293
K7GWTrojan ( 00569c651 )
Cybereasonmalicious.c79478
BitDefenderThetaGen:NN.ZevbaF.34634.tm1@aS8A63hO
CyrenW32/VBInject.AEB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ClamAVWin.Malware.Etej-9789141-0
KasperskyHEUR:Trojan.Win32.Vebzenpak.vho
Ad-AwareTrojan.GenericKDZ.68293
F-SecureHeuristic.HEUR/AGEN.1136738
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
EmsisoftTrojan.GenericKDZ.68293 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Vebzenpak.gub
AviraHEUR/AGEN.1136738
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Emotet.AR!MTB
ArcabitTrojan.Generic.D10AC5
ZoneAlarmHEUR:Trojan.Win32.Vebzenpak.vho
GDataTrojan.GenericKDZ.68293
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R355379
VBA32BScope.Trojan.Mansabo
MAXmalware (ai score=85)
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Injector.EMNI
RisingTrojan.Kryptik!1.C606 (CLASSIC)
YandexTrojan.Injector!21fFZSdYfpQ
eGambitUnsafe.AI_Score_67%
FortinetW32/TrickBot.QNID!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.EMNI?

Win32/Injector.EMNI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment