Malware

Win32/Injector.EOKM information

Malware Removal

The Win32/Injector.EOKM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EOKM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Injector.EOKM?


File Info:

crc32: 4C9EA374
md5: 30dcecd1717926af1a3ece326d5a3f77
name: 30DCECD1717926AF1A3ECE326D5A3F77.mlw
sha1: c7fc084d2b6016f8b6a230687f8d12c7ced71572
sha256: a95d4bd25849a4e0a3ce3ba51c98b3c713bcb7afafdabdb2de8c77653cae0d47
sha512: 7de77092952df61e4bf084c4875b8cb62d0bc4c0c92a78d7508946a34aff97e9dfe6c2ed61665024cfc162ade7df0c3d1fbc4f8e0a284559a9a0b28e6c6c33de
ssdeep: 6144:OYYVstvLGtELbMUTKZ6/BtdTDa95jJL9CeIogCQNubbjykQh:aSityjKU/BtJDgtJL9aog5u3jw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EOKM also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36291944
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.36291944
MalwarebytesBackdoor.Remcos
VIPRETrojan.Win32.Generic.pak!cobra
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057739e1 )
BitDefenderTrojan.GenericKD.36291944
K7GWTrojan ( 0057739e1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D229C568
CyrenW32/Trojan.KOBS-6502
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaTrojan:Win32/SpyNoon.f41c2395
NANO-AntivirusTrojan.Win32.Androm.ikbioz
TencentWin32.Trojan.Agent.Ljui
Ad-AwareTrojan.GenericKD.36291944
SophosMal/Generic-S
ComodoMalware@#2mg292yn3718p
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Loader.701
TrendMicroBackdoor.Win32.ANDROM.THBOCBA
McAfee-GW-EditionBehavesLike.Win32.Vopak.fc
FireEyeGeneric.mg.30dcecd1717926af
EmsisoftTrojan.GenericKD.36291944 (B)
IkarusTrojan-Spy.Agent
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1140854
Antiy-AVLTrojan[Backdoor]/Win32.Androm
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftAdware.Win32.Linkury.oa
MicrosoftTrojan:Win32/SpyNoon.ST!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
GDataWin32.Backdoor.Remcos.4QKHMW
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4320688
McAfeeRDN/Generic.cf
MAXmalware (ai score=99)
VBA32Trojan.Agent
CylanceUnsafe
ESET-NOD32a variant of Win32/Injector.EOKM
TrendMicro-HouseCallBackdoor.Win32.ANDROM.THBOCBA
RisingTrojan.Injector!1.D261 (CLOUD)
YandexTrojan.Igent.bVhxDS.31
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent!tr
BitDefenderThetaGen:NN.ZedlaF.34804.am4@ayLFbhc
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.171792
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Win32/Backdoor.Androm.HyoDCNoA

How to remove Win32/Injector.EOKM?

Win32/Injector.EOKM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment