Malware

Win32/Injector.EONA removal

Malware Removal

The Win32/Injector.EONA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EONA virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EONA?


File Info:

crc32: 2E79A811
md5: fc7ebc94472ed9f845d5b7e16cb55af9
name: FC7EBC94472ED9F845D5B7E16CB55AF9.mlw
sha1: 5fa29d2b768a40cb42c36f875a9d96b76b8637dc
sha256: 6b403146e3a8b29755915a0577f4411bc1b00e753bef05cb8cc8980841257db0
sha512: 5e9aed865bc24dd8e89d8d2be5f7bd28c73a4ebcb3dce4a624c69614c864b5848f249236432cc33e0efbb47d893d7317a3cc70c34237b690f681aa5abf58d24a
ssdeep: 12288:h+/wU4JXS2NqyhEkgeWxOw6BMLGE7qQzSPrp2Vy+NkyWyaz/Ph+dXV4:42JpDZHWxOwkYq9rp2VXNkyvyRKV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright leash
FileVersion: 3.1.0.14
CompanyName: leash
LegalTrademarks: village
Comments: structure
ProductName: crossing
FileDescription: diet
Translation: 0x0409 0x04e4

Win32/Injector.EONA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45709477
ALYacTrojan.GenericKD.45709477
CylanceUnsafe
SangforSuspicious.Win32.Artemis.9DB3ED7D6CE7
K7AntiVirusTrojan ( 005779851 )
BitDefenderTrojan.GenericKD.45709477
K7GWTrojan ( 005779851 )
Cybereasonmalicious.4472ed
CyrenW32/Androm.BU.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Gamarue-9830641-0
KasperskyHEUR:Trojan.Win32.Injects.gen
AlibabaTrojan:Win32/Androm.14d7581f
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Injector!8.C4 (TFE:1:J2snOAN1QmM)
Ad-AwareTrojan.GenericKD.45709477
SophosMal/Generic-S
ComodoMalware@#1gbazchg2n6vy
F-SecureTrojan.TR/Injector.hbzsm
DrWebTrojan.DownLoader36.40268
TrendMicroTROJ_FRS.0NA103BC21
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
FireEyeGeneric.mg.fc7ebc94472ed9f8
EmsisoftTrojan.Injector (A)
IkarusTrojan.Win32.Injector
AviraTR/Injector.imftm
Antiy-AVLTrojan/Win32.Injects
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
GridinsoftAdware.Win32.Linkury.oa
ArcabitTrojan.Generic.D2B978A5
ZoneAlarmHEUR:Trojan.Win32.Injects.gen
GDataWin32.Trojan-Stealer.SnakeKeyLogger.VTK6VF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Androm.R365907
McAfeeArtemis!FC7EBC94472E
MAXmalware (ai score=84)
VBA32Trojan.Woreflint
MalwarebytesSpyware.LokiBot
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.EONA
TrendMicro-HouseCallTROJ_FRS.0NA103BC21
TencentWin32.Trojan.Injects.Efkw
FortinetW32/Androm.ZUM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.Androm.HoMASOwA

How to remove Win32/Injector.EONA?

Win32/Injector.EONA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment