Malware

Win32/Injector.EPHU removal instruction

Malware Removal

The Win32/Injector.EPHU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPHU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EPHU?


File Info:

crc32: 805080CB
md5: 3f695fa46992bd20300728e9245c87f8
name: 3F695FA46992BD20300728E9245C87F8.mlw
sha1: 83d7a6cb77eff285ed7b1950438fa3573d5b31fd
sha256: e0f53d67eb5d4a5bab2f6d0bbaff502896e12572b97bf0350c88cfac3fcc5b8f
sha512: 04e7fdd44934be48435ae8ccb143b8d0d95a1ea002a549da5ed7b7a39e9bdcb1be1d942200ce39b3119d4bf29d0eacc9fdefed3dc38e1d25b689e747f9348aef
ssdeep: 1536:1HDgHBRiC/5r4b01V/M7FWf0Nq7Iz/a2GeD:JY4+542/YFWfea2Ge
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: rammier
FileVersion: 1.00
CompanyName: Asso Filler
ProductName: Asso Filler
ProductVersion: 1.00
FileDescription: Asso Filler
OriginalFilename: rammier.exe

Win32/Injector.EPHU also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.b77eff
ESET-NOD32a variant of Win32/Injector.EPHU
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan.Win32.Vebzenpak
SophosML/PE-A
BitDefenderThetaGen:NN.ZevbaF.34688.fm0@am7Sfqfb
FireEyeGeneric.mg.3f695fa46992bd20
eGambitUnsafe.AI_Score_91%
MicrosoftTrojan:Win32/Wacatac.B!ml
IkarusWin32.Outbreak
FortinetMalicious_Behavior.SB
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Injector.EPHU?

Win32/Injector.EPHU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment