Malware

Win32/Injector.EOIF malicious file

Malware Removal

The Win32/Injector.EOIF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EOIF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EOIF?


File Info:

crc32: 49F2B10D
md5: cb3b77181a200f9b066fd29e4431ad0f
name: CB3B77181A200F9B066FD29E4431AD0F.mlw
sha1: 0019eab67d15bf22a9e90345bf7281b4f0c11d5f
sha256: d94aa8eba8dce581912552261b549bb8bcf04e8380fa68dc525c0d94236b761b
sha512: 727c614587570ce6ecf1489dcce3fd0e7415f83937dd9b349a3b055f4568fcdd319978310c47c01dcb2bc151426807d0812579e922dee4ffc329e3e8117885e3
ssdeep: 1536:nz2K0+KowzEQVKnQrIskYv67Z6ojCaXDdoDIlB:zSuwoLyaBo6B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Rombudd
FileVersion: 1.00
CompanyName: Longines
ProductName: Longines
ProductVersion: 1.00
OriginalFilename: Rombudd.exe

Win32/Injector.EOIF also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45635457
FireEyeGeneric.mg.cb3b77181a200f9b
MalwarebytesGeneric.Malware/Suspicious
BitDefenderTrojan.GenericKD.45635457
CyrenW32/Kryptik.DCX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:DangerousObject.Multi.Generic
Ad-AwareTrojan.GenericKD.45635457
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Fareit.cm
EmsisoftTrojan.GenericKD.45634842 (B)
GDataWin32.Trojan-Downloader.GuLoader.0RE5A5
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 90)
McAfeeGenericRXAA-FA!CB3B77181A20
MAXmalware (ai score=84)
ESET-NOD32a variant of Win32/Injector.EOIF
eGambitUnsafe.AI_Score_98%
FortinetW32/EOIF!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Injector.EOIF?

Win32/Injector.EOIF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment