Malware

Win32/Injector.EPHM removal

Malware Removal

The Win32/Injector.EPHM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPHM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Looks up the external IP address
  • A process sent information about the computer to a remote location.
  • Anomalous binary characteristics

Related domains:

api.ipify.org
extilivelly.com

How to determine Win32/Injector.EPHM?


File Info:

crc32: 41B4D350
md5: 3a1a3003abe93262fc4d7fa7627fbc36
name: 3A1A3003ABE93262FC4D7FA7627FBC36.mlw
sha1: 93fe134cebebed9571338b699c1e09fc0e80e80b
sha256: 50c79e0302806fba97663b7d6d9d2bb6640e4eec395adb7f49ca777e9e81e15e
sha512: c59abcf7ac87224606f00673739222470f4de708d500c6f6b5c64174c01966b72f2d4db670649d1a50da2abb442a02a2262fcf669890ea113af0587bacd7023c
ssdeep: 12288:/gHaqhhq3Pf7AH3cVNStQQF1msx0gU//dMPDLMV://chYusVNVQK0U/d8W
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EPHM also known as:

DrWebTrojan.Chanitor.59
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Injector.f8c0b9c9
K7GWTrojan ( 0057c0a71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPHM
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyHEUR:Trojan-Dropper.Win32.Safebits.gen
BitDefenderTrojan.GenericKD.46532685
MicroWorld-eScanTrojan.GenericKD.46532685
SophosMal/Generic-R + Mal/EncPk-APY
McAfee-GW-EditionBehavesLike.Win32.Worm.bh
FireEyeGeneric.mg.3a1a3003abe93262
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_64%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Hancitor.VAM!MTB
AegisLabTrojan.Win32.Generic.l6Vk
GDataWin32.Trojan.Kryptik.GMUTAQ
McAfeeRDN/Generic.grp
MAXmalware (ai score=84)
VBA32BScope.Trojan.Bsymem
MalwarebytesMalware.AI.3848947555
TrendMicro-HouseCallTROJ_GEN.R002H0DFN21
FortinetW32/EPHM!tr
AVGWin32:InjectorX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.EPHM?

Win32/Injector.EPHM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment