Malware

Should I remove “Win32/Injector.EPMI”?

Malware Removal

The Win32/Injector.EPMI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPMI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Sutu
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EPMI?


File Info:

crc32: 9CE22EAC
md5: be5a85f85d011252e63cab4566239280
name: BE5A85F85D011252E63CAB4566239280.mlw
sha1: 72a8f524a3b449b3c459cdfe4a7b6c1c46b0dcdd
sha256: 057144f38e786ee18295c76f3f06a975fc342358a5d6ba049000ca0fe44e8179
sha512: 732e41dc029f793c9076904909ad3fe222d127dd47bec8075b682dd2a4505be38e76a3b764271ca2930945bf31c0e39f48c42295d703595247c7ba6cac5829b9
ssdeep: 1536:Q/Qq7xbuNxA3JhkGpwPRRHkOVPVXYstBRQeag24T1f:sYN63cWqRHkOVPVostrQeTJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0430 0x04b0
LegalCopyright: Yonyou Network
InternalName: pansy
FileVersion: 1.00
CompanyName: Yonyou Network
LegalTrademarks: Yonyou Network
Comments: Yonyou Network
ProductName: Yonyou Network
ProductVersion: 1.00
FileDescription: Yonyou Network
OriginalFilename: pansy.exe

Win32/Injector.EPMI also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.2301
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Injector.85fc2515
K7GWTrojan ( 0057dbe71 )
CyrenW32/VBKrypt.AVS.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EPMI
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Mucc.ohj
BitDefenderTrojan.GenericKD.46445821
MicroWorld-eScanTrojan.GenericKD.46445821
Ad-AwareTrojan.GenericKD.46445821
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34722.im0@aKeyuTfG
VIPRELooksLike.Win32.Beebone.a (v)
TrendMicroTrojanSpy.Win32.MUCC.USMANF721
McAfee-GW-EditionBehavesLike.Win32.Fareit.ct
FireEyeGeneric.mg.be5a85f85d011252
EmsisoftTrojan.GenericKD.46445821 (B)
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2C4B4FD
AegisLabTrojan.Win32.Mucc.4!c
GDataTrojan.GenericKD.46445821
AhnLab-V3Trojan/Win.GuLoader.R424598
McAfeePWS-FCZB!BE5A85F85D01
MAXmalware (ai score=83)
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.MUCC.USMANF721
YandexTrojan.AvsArher.bTx33N
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/EPMI!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Injector.EPMI?

Win32/Injector.EPMI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment