Malware

Win32/Injector.EPOJ removal tips

Malware Removal

The Win32/Injector.EPOJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPOJ virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EPOJ?


File Info:

crc32: 48B97431
md5: 40d0d344b02fe4caaafcf904bb3c4d53
name: 40D0D344B02FE4CAAAFCF904BB3C4D53.mlw
sha1: 8bced6d680a16550378d5f38b2788b89bb9caa7f
sha256: f8cd7fa6a393bb82922655379266b0f96a2b9481f5938447a5f0158d76f347ba
sha512: 444163e7a980917cc4ef8631ee72de7bda177680e1bb6087b2576ebf43a7828b194a4ee098e03a1ba7dc4b5354282f211dd6649dd2746fd5fbadc02962e547c9
ssdeep: 24576:CX2aUAKvTWIBwUo49MYa4HvjBT4q/XQBoG:CX5tsddnG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EPOJ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.63178
CynetMalicious (score: 100)
ALYacTrojan.GenericFCA.Agent.8189
SangforBackdoor.Win32.Remcos.gen
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057e5ca1 )
Cybereasonmalicious.680a16
CyrenW32/Trojan.VVQO-5154
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPOJ
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.37131857
MicroWorld-eScanTrojan.GenericKD.37131857
Ad-AwareTrojan.GenericKD.37131857
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.37131857
EmsisoftTrojan.GenericFCA.Agent.8189 (B)
AviraTR/Injector.wxrvl
eGambitPE.Heur.InvalidSig
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitTrojan.Generic.D2369651
AegisLabTrojan.Win32.Remcos.m!c
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataWin32.Trojan.Agent.JZE5NU
AhnLab-V3Trojan/Win.Generic.C4531761
McAfeeArtemis!40D0D344B02F
MAXmalware (ai score=85)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0DFL21
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.EPOJ?

Win32/Injector.EPOJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment