Malware

Win32/Injector.EQRS malicious file

Malware Removal

The Win32/Injector.EQRS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQRS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Win32/Injector.EQRS?


File Info:

name: 50457159F17F05CAAFFE.mlw
path: /opt/CAPEv2/storage/binaries/13d4188437fd7caf662393052ef82808bf70cdb5e31fcc2f162ad2dffad377aa
crc32: E71EBFCA
md5: 50457159f17f05caaffe059b812a34b3
sha1: 1e714a93492ed274ffd977454327ad203ab5350e
sha256: 13d4188437fd7caf662393052ef82808bf70cdb5e31fcc2f162ad2dffad377aa
sha512: 3fec594f9fd1fbfb596d3dc818f7c51c5aafe7396952b5000921145637e4317ef708cc2a14f2be06f0b4f5c8db98b9419384e12163124aaef6ef39e2fa2dd0af
ssdeep: 6144:rGiFz3RuO7DbGGmH3uNOyb2HOh0STed7gB7ZaEPlrtIvhAC7+P1KoxU3qB3pAk:Bz3PHGGY3ukqSOpUGZauleZfynAk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B364230CEFD4C267F7254971DDF647A687BA9484409D022EAFB41FBE3A7665903202CB
sha3_384: 08bde2508dce136bf9411b2521bd49760b1ae19e6b74942ccb3d29944eb9b156b2e4e5f54cae5577995a8ff6ef373867
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Win32/Injector.EQRS also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Siggen15.63208
MicroWorld-eScanTrojan.GenericKD.47569500
FireEyeTrojan.GenericKD.47569500
ALYacTrojan.GenericKD.47569500
MalwarebytesTrojan.Injector
K7AntiVirusTrojan ( 0058b6811 )
AlibabaTrojan:Win32/Injector.f684e8a7
K7GWTrojan ( 0058b6811 )
Cybereasonmalicious.9f17f0
ArcabitTrojan.Generic.D2D5DA5C
CyrenW32/Injector.ANJ.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EQRS
TrendMicro-HouseCallTROJ_FRS.VSNTL621
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.GenericKD.47569500
TencentWin32.Trojan-spy.Noon.Ssgr
Ad-AwareTrojan.GenericKD.47569500
EmsisoftTrojan.GenericKD.47569500 (B)
ComodoTrojWare.Win32.Agent.sccwp@0
TrendMicroTROJ_FRS.VSNTL621
McAfee-GW-EditionRDN/Formbook
Paloaltogeneric.ml
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1141486
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojanSpy:Win32/Swotter.A!bit
GDataWin32.Trojan-Stealer.FormBook.ECXH7M
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4817276
McAfeeRDN/Formbook
MAXmalware (ai score=86)
APEXMalicious
FortinetW32/Kryptik.EQRK!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A

How to remove Win32/Injector.EQRS?

Win32/Injector.EQRS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment