Malware

Win32/Injector.EOEH (file analysis)

Malware Removal

The Win32/Injector.EOEH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EOEH virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EOEH?


File Info:

crc32: 3B0336AE
md5: 217c12cc68f0b8e5043b65fdbf9d32d6
name: 217C12CC68F0B8E5043B65FDBF9D32D6.mlw
sha1: bbcb2d0178fa4a45f0a01b1e7f7b7f83b3a8a4e6
sha256: 623ae5233a81d26b9d96a15655c193acf888dca51c3095da3f82664589c523c7
sha512: c93c510293bdb319ef43e85924f20f933ecb90b9190580d68c4e59684ae390cc8598cc2fea4f35811f905eb3853fd29aa968baeaebb88ed139c075b26a94301e
ssdeep: 12288:5fLWNFPxOxLraMCrqfZW562wzVAoQKzT1Asvi56LffGfbWj:tynGraMCrV62mVAkzFvHLffGyj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000-2009 Heaventools Software
InternalName: Document
FileVersion: 1.92.0.98
CompanyName: Document Software
LegalTrademarks: Document is a trademark of Heaventools Software
Comments:
ProductName: Documentlorer
ProductVersion: 1.92.0.98
FileDescription: Document
OriginalFilename: Document
Translation: 0x0000 0x04e3

Win32/Injector.EOEH also known as:

BkavW32.AIDetectVM.malware2
FireEyeGeneric.mg.217c12cc68f0b8e5
Qihoo-360Win32/Trojan.Ransom.ed7
McAfeeFareit-FZO!217C12CC68F0
CylanceUnsafe
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.Blocker.gen
DrWebTrojan.DownLoader36.31514
McAfee-GW-EditionFareit-FZO!217C12CC68F0
MicrosoftTrojan:Win32/CryptInject!ml
ZoneAlarmHEUR:Trojan-Ransom.Win32.Blocker.gen
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZelphiF.34700.SG2@auNr6Ldi
ESET-NOD32a variant of Win32/Injector.EOEH
TrendMicro-HouseCallTROJ_GEN.R002H06LS20
RisingTrojan.Generic@ML.96 (RDML:XzmNNL0cDixHUMSXw+iDhg)
eGambitPE.Heur.InvalidSig
FortinetW32/Injector.ENXX!tr
AVGWin32:InjectorX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.EOEH?

Win32/Injector.EOEH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment