Malware

Win32/Injector.EPTS information

Malware Removal

The Win32/Injector.EPTS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPTS virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.dyndns.org
freegeoip.app

How to determine Win32/Injector.EPTS?


File Info:

crc32: 6DCF46D2
md5: 9b0369bd03a34a6e4999c2cb91fff715
name: 9B0369BD03A34A6E4999C2CB91FFF715.mlw
sha1: aa85ecf4a1b666e2eba2c98dcecee50401e0666e
sha256: 09c99cbd62e78fc032d329b5fa479ad6fb5ebb4db11b29b2c528cb799ea9e283
sha512: a1f70d88e073c2c48d09675abdf600cf16856d445a0970285490abb6eb19fa3193ddaa1b75df65f7b622fa30e9501a7291d02630f7b2e53deb90c24149d0b28f
ssdeep: 6144:4qjI2XrSaKwFYXJIJESHowuvW4GOXpY4OIa2kqNXSMzJCKKg:1rrPFrEdneTOXOBpqNXSIx7
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Injector.EPTS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057eb291 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.CloudSword.BAB6738F
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0057eb291 )
Cybereasonmalicious.d03a34
CyrenW32/Injector.AJN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPTS
APEXMalicious
AvastNSIS:RATX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Stealer.gen
BitDefenderDeepScan:Generic.Ransom.CloudSword.BAB6738F
MicroWorld-eScanDeepScan:Generic.Ransom.CloudSword.BAB6738F
Ad-AwareDeepScan:Generic.Ransom.CloudSword.BAB6738F
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
FireEyeGeneric.mg.9b0369bd03a34a6e
EmsisoftDeepScan:Generic.Ransom.CloudSword.BAB6738F (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealer.gen
GDataDeepScan:Generic.Ransom.CloudSword.BAB6738F
AhnLab-V3Trojan/Win.Generic.R431185
McAfeeArtemis!9B0369BD03A3
MAXmalware (ai score=81)
VBA32Backdoor.Androm
MalwarebytesMalware.AI.3611274439
YandexTrojan.Slntscn24.bVVB1s
FortinetW32/Injector.AFC!tr
AVGNSIS:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.EPTS?

Win32/Injector.EPTS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment