Malware

Win32/Injector.EOAL removal guide

Malware Removal

The Win32/Injector.EOAL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EOAL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com
brice.ac.ug
darkangel.ac.ug

How to determine Win32/Injector.EOAL?


File Info:

crc32: 485A7B06
md5: 20b4ed91510de8b2766a7b27b643a007
name: 20B4ED91510DE8B2766A7B27B643A007.mlw
sha1: e52812e0a3a17a291f524bde23a7dea44339bbf3
sha256: 0733d640a833a24e6c37c8085a6e22ba3245eee995c83edf79f20efa327d365a
sha512: bad5c56aeb9b57c7b4591f34f41a157fc60e5038eeef82aaaa297a267bfb6c69ad8d52a9b60142c502756f56829c8a44840c620e1191458135fbb5b319feed0f
ssdeep: 24576:/axyj3UlpY02W9pNydU50sTmJf2fU+NAmAOLm+t:/ac3UoW9OGxTmJ6emACm+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 1.00
InternalName: awuiefhrenjvcdfejkldj
FileVersion: 1.00
OriginalFilename: awuiefhrenjvcdfejkldj.exe
ProductName: Mevcsfojzbvcefwejriowar7248

Win32/Injector.EOAL also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.20b4ed91510de8b2
Qihoo-360Generic/HEUR/QVM20.1.C387.Malware.Gen
CylanceUnsafe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EOAL
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Injector!1.C6AF (CLASSIC)
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionArtemis
SophosML/PE-A
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Caynamer.A!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan-Stealer.PSWSteal.OGRW28
CynetMalicious (score: 100)
McAfeeArtemis!20B4ED91510D
MalwarebytesSpyware.PasswordStealer
eGambitPE.Heur.InvalidSig
AVGFileRepMetagen [Malware]
Cybereasonmalicious.0a3a17

How to remove Win32/Injector.EOAL?

Win32/Injector.EOAL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment