Malware

What is “Win32/Injector.EPQI”?

Malware Removal

The Win32/Injector.EPQI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPQI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.EPQI?


File Info:

crc32: EF9857AF
md5: fbb86a0ca6bdefd28a6c70f7cd3040c4
name: FBB86A0CA6BDEFD28A6C70F7CD3040C4.mlw
sha1: 48021810130cd715a6970f51a0ef8272d0642fdd
sha256: 07af0ffdb9e42eb6ca145708be323b7641311d943d28ba746d5f16dd4c5a3eed
sha512: 8c8abb2ff7d56c886ffaba40f4448bbdf5c52239c9b4352198eca2d3f07c857ced4f8f6fb649ce36f9f8e4ec2a36bfbd0fe77b983b33b8147b37b300ff1246fe
ssdeep: 6144:iqjIKDFpnLrM+xzNbwww/tPhf5W969FuX:zpDjPM+TkBu
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Injector.EPQI also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Agent.Swotter
CylanceUnsafe
SangforSuspicious.Win32.Artemis.A2F50400DEC2
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057ec631 )
Cybereasonmalicious.0130cd
CyrenW32/Injector.AIQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPQI
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.GenericKD.37169792
MicroWorld-eScanTrojan.GenericKD.37169792
Ad-AwareTrojan.GenericKD.37169792
SophosMal/Generic-S + Troj/Formbo-ANL
ComodoTrojWare.Win32.UMal.niqgq@0
McAfee-GW-EditionBehavesLike.Win32.Vopak.cc
FireEyeGeneric.mg.fbb86a0ca6bdefd2
EmsisoftTrojan.GenericKD.37169792 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:Win32/Swotter.A!bit
AegisLabTrojan.Win32.Noon.l!c
GDataWin32.Trojan-Stealer.FormBook.TX1ZU6
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=88)
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.F0D1C00G121
YandexTrojan.Slntscn24.bVVB1s
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.1!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HyoDSUUA

How to remove Win32/Injector.EPQI?

Win32/Injector.EPQI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment