Malware

Win32/Injector.ENTV malicious file

Malware Removal

The Win32/Injector.ENTV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ENTV virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

How to determine Win32/Injector.ENTV?


File Info:

crc32: 2947014E
md5: 7f4c5c493a28228c18fb6b867dfbf1c5
name: 7F4C5C493A28228C18FB6B867DFBF1C5.mlw
sha1: 78390275b89821dfb0029737faa0116201e1d7fa
sha256: 3047aab5235fc377107a2106863cc379cfce34446c34de688ff84774f59b3de9
sha512: c927ce9d7ef597be3d454155430a1576c8592f0190a8ac5c4c89ce209728a9fc8a11bc2da2780abc92342fd10a27ca09bd19b3b717d413a2a314b6f21b6c9632
ssdeep: 24576:pDi/+kdKXmIRwQJ1qkxKtze/SI13/8SZygfMCPuXmpulT:eLIiYoaKVWZHMCPuXRF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Co9gfd324p.
InternalName:
FileVersion: 592341t6
CompanyName: v43fvguyitr
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 817647453256
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Win32/Injector.ENTV also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.338505
FireEyeGeneric.mg.7f4c5c493a28228c
ALYacGen:Variant.Zusy.338505
SangforMalware
K7AntiVirusTrojan ( 00572b511 )
BitDefenderGen:Variant.Zusy.338505
K7GWTrojan ( 00572b511 )
Cybereasonmalicious.93a282
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
RisingTrojan.Injector!1.CEB9 (CLASSIC)
Ad-AwareGen:Variant.Zusy.338505
SophosTroj/Agent-AJFK
DrWebTrojan.PWS.Stealer.26517
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Fareit.th
EmsisoftTrojan.Injector (A)
IkarusTrojan.Inject
MicrosoftPWS:Win32/Fareit!ml
ArcabitTrojan.Zusy.D52A49
GDataGen:Variant.Zusy.338505
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fareit.R354591
McAfeeFareit-FZN!7F4C5C493A28
MAXmalware (ai score=84)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
ESET-NOD32a variant of Win32/Injector.ENTV
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ENTV!tr
BitDefenderThetaAI:Packer.6045CD0821
AVGWin32:CoinminerX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen

How to remove Win32/Injector.ENTV?

Win32/Injector.ENTV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment