Malware

About “Win32/Injector.EPIK” infection

Malware Removal

The Win32/Injector.EPIK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPIK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.EPIK?


File Info:

crc32: 9575AEB4
md5: 19d109dbe9203696382a0fff8c8712b2
name: 19D109DBE9203696382A0FFF8C8712B2.mlw
sha1: bdbe44ed8fa049f5c336c78d2323c1eab6b6bd43
sha256: 059980c8a397a5ba2f10ab5744415455c9989710e34c39061a2c601b9760d75a
sha512: 4907f64ea33af6560a4149e4bc6bed38adbe45c090cfc92778c53a75bf23653bac57393f9d83cbfbf5b807b9386a381a764d48526a3c31117e67a3ab28d52660
ssdeep: 6144:jgORakBMh4zWZgpZYx9dM7+FbJDpMqxth4TVbe:jgIu63pZYxA7+FdDuCtCVbe
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Injector.EPIK also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.11830
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.NanoBot
ALYacTrojan.GenericKD.36890471
CylanceUnsafe
SangforBackdoor.Win32.NanoBot.gen
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d8fa04
CyrenW32/NSIS_Agent.D.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EPIK
ZonerTrojan.Win32.110734
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.NanoBot.gen
BitDefenderTrojan.GenericKD.36890471
MicroWorld-eScanTrojan.GenericKD.36890471
Ad-AwareTrojan.GenericKD.36890471
SophosML/PE-A + Troj/NanoCr-LU
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.dc
FireEyeGeneric.mg.19d109dbe9203696
EmsisoftTrojan.GenericKD.36890471 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Gen.pak
AviraHEUR/AGEN.1142331
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Nsis.Spy.Gen.2
AegisLabTrojan.Win32.NanoBot.m!c
GDataMSIL.Backdoor.Nancat.ZH3PKD
McAfeeArtemis!19D109DBE920
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_GEN.F0D1C00ED21
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusWin32.SuspectCrc
FortinetW32/Androm.29!tr
AVGWin32:InjectorX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.EPIK?

Win32/Injector.EPIK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment