Malware

How to remove “Win32/Injector.EQDS”?

Malware Removal

The Win32/Injector.EQDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQDS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.EQDS?


File Info:

crc32: 3B88BA0D
md5: 2be4cef3c2e36231b7adcb4a159a00eb
name: 2BE4CEF3C2E36231B7ADCB4A159A00EB.mlw
sha1: cd463062a6a40ee0297aaa35213d6f4ace727902
sha256: e45126e1fced974616b02a44e0a0d6c17d3788161010dd18a1429e69b5f6a947
sha512: 15671497a53ec007e27181c1433d05accbe61965856e66c01fda14ca5dcc0cba547c18d95657f0997eaca078fa8a19ccf7307e60ef2a0bc0ce99d627216f6da2
ssdeep: 1536:cO8LKTwVS4WXIf+DqjxrrkKvLU2da81pOMI/:q+ISXi+Dq1/jvLhda81Do
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: AKER
FileVersion: 1.00
CompanyName: FutuClass
Comments: FutuClass
ProductName: FutuClass
ProductVersion: 1.00
FileDescription: FutuClass
OriginalFilename: AKER.exe

Win32/Injector.EQDS also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.WBVB.o!c
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 00585f321 )
K7AntiVirusTrojan ( 00585f321 )
CyrenW32/VBKrypt.BAM.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EQDS
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyUDS:Worm.Win32.WBVB
BitDefenderTrojan.GenericKD.37626112
MicroWorld-eScanTrojan.GenericKD.37626112
Ad-AwareTrojan.GenericKD.37626112
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaCO.34170.fm0@aa!u9mmi
McAfee-GW-EditionBehavesLike.Win32.Fareit.mh
FireEyeGeneric.mg.2be4cef3c2e36231
EmsisoftTrojan.GenericKD.37626112 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.37626112
AhnLab-V3Trojan/Win.Generic.R442435
McAfeeGuLoader-FDCG!2BE4CEF3C2E3
MAXmalware (ai score=82)
PandaTrj/RnkBend.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00IM21
IkarusWin32.SuspectCrc
FortinetMalicious_Behavior.SB
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Injector.EQDS?

Win32/Injector.EQDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment