Malware

Should I remove “Win32/Injector.EQYQ”?

Malware Removal

The Win32/Injector.EQYQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQYQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Win32/Injector.EQYQ?


File Info:

name: C8DF5E6047CD338743E3.mlw
path: /opt/CAPEv2/storage/binaries/5111f4fa05b89a9d727c4686485acedc16553a7715fd36776c68972acf8e5382
crc32: DE000BCA
md5: c8df5e6047cd338743e32c7e79067a45
sha1: 848cdb2e9b7415ca7689b74ffd076fb92a8637a4
sha256: 5111f4fa05b89a9d727c4686485acedc16553a7715fd36776c68972acf8e5382
sha512: c18533cd152b2ea6c395d6224f0dcbc73f3583bb4b8b902cf967c906a5c5df634976741a9f90977fa05e487277d79c4ac7e85f5216921f4c78bde1abd7f36436
ssdeep: 6144:owP+u6fNm3qOw79L8xo0YpbxQdqCL24ON9Uu+weOBVKeAYazi/rMcBiccMezviD+:bnEx8xeptQdqC7oOKeOBVzIETB7cMaUW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F64120F22E4CCF5CA256A704C3FD779EEF46A510791161363A80E3F66B32D61A1B0D6
sha3_384: 19acc7252b7353cd9b9b35c7f58952d656909843e7603d6df72930aecb1cc3983d17b939d0717a6e6d026cba358cba44
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Win32/Injector.EQYQ also known as:

MicroWorld-eScanTrojan.GenericKD.48035597
FireEyeTrojan.GenericKD.48035597
CAT-QuickHealTrojanspy.Noon
McAfeeArtemis!C8DF5E6047CD
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 0058d4be1 )
AlibabaTrojan:Win32/ObfusInjector.ebdc70ab
K7GWTrojan ( 0058d4be1 )
Cybereasonmalicious.047cd3
CyrenW32/Injector.ATO.gen!Eldorado
SymantecPacked.NSISPacker!g10
ESET-NOD32a variant of Win32/Injector.EQYQ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Malwarex-9937231-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.48035597
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Backdoor.Agent.Tbit
EmsisoftTrojan.GenericKD.48035597 (B)
TrendMicroTROJ_FRS.0NA103AM22
McAfee-GW-EditionRDN/Generic.grp
SophosMal/Generic-S + Troj/Formbo-BXM
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.dugo
AviraTR/AD.Swotter.ckfgb
Antiy-AVLTrojan/Generic.ASMalwS.3514879
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:Win32/Swotter.A!bit
ViRobotTrojan.Win32.Z.Risis.334556
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataTrojan.GenericKD.48035597
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ObfusInjector.R467391
VBA32BScope.TrojanPSW.Banker
ALYacTrojan.Agent.FormBook
MAXmalware (ai score=82)
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_FRS.0NA103AM22
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.NSIS.Agent
FortinetW32/Kryptik.EQXP!tr
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.EQYQ?

Win32/Injector.EQYQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment