Malware

Win32/Injector.EQDH removal guide

Malware Removal

The Win32/Injector.EQDH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQDH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Looks up the external IP address
  • Steals private information from local Internet browsers
  • Attempts to identify installed AV products by installation directory
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.dyndns.org
freegeoip.app

How to determine Win32/Injector.EQDH?


File Info:

crc32: BF0176E4
md5: 8558ee81ee676e88db41bbe72f339f84
name: 8558EE81EE676E88DB41BBE72F339F84.mlw
sha1: 6c7e5d9108c3fcaa6946011e56bdaf20fde69a66
sha256: 290c8950d6cce06c3299c4fc36f25312c11a19abd0c1ede6809b764da15d4951
sha512: 154113aaf7e3673f2eaa91dcefc1d1179a1b9d2781d92c8773c9b6fe6b4fb9be7e262b5dd0fb55cc10484ae5c0a0657f88731b5fe7c740ba763b0c4f6fe99e73
ssdeep: 6144:38LxBpKq+b3EiHoclEFsS8vgtKioVL5Mle3asMo6NqlSLanufldhs:UKq+gMn2P8vgxzleKsWza6e
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: vrzle
FileVersion: 15.15.13.17.
CompanyName: yksr
LegalTrademarks: qwblyibotkiaynut
Comments: yhixgmwsjijirn
ProductName: goaqwsoutplhpnn
FileDescription: kntp
Translation: 0x0000 0x04e4

Win32/Injector.EQDH also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CyrenW32/Injector.ALJ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.EQDH
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyUDS:Trojan-PSW.Win32.Stealer.gen
BitDefenderTrojan.NSISX.Spy.Gen.2
MicroWorld-eScanTrojan.NSISX.Spy.Gen.2
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.ICLoader.fc
FireEyeGeneric.mg.8558ee81ee676e88
EmsisoftTrojan.NSISX.Spy.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitTrojan.NSISX.Spy.Gen.2
GDataMSIL.Trojan-Spy.SnakeKeylogger.PHT42A
McAfeeRDN/Snakekeylogger
MAXmalware (ai score=86)
MalwarebytesMalware.AI.3287555329
TrendMicro-HouseCallTROJ_GEN.F0D1C00IK21
IkarusTrojan.NSIS.Agent
FortinetW32/Swotter.LQZI!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Injector.EQDH?

Win32/Injector.EQDH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment