Malware

Should I remove “Win32/Injector.EQZR”?

Malware Removal

The Win32/Injector.EQZR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQZR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the AgentTeslaV3 malware family

How to determine Win32/Injector.EQZR?


File Info:

name: 2365543F0624DB31C512.mlw
path: /opt/CAPEv2/storage/binaries/1cba0c299f85ce468745ca72de543ce885a01364e243463806c7d06e29d196c0
crc32: 85C20D67
md5: 2365543f0624db31c5126dafeebeda31
sha1: 828ee9c131a2dbc6f5239a6837fe23c205396ddc
sha256: 1cba0c299f85ce468745ca72de543ce885a01364e243463806c7d06e29d196c0
sha512: 265692fbfad1be68ef608c9ea64320cfbd67ced63c17413f242234cdd8ff58504751a0a07ab47d3f1edf7fa5338d667b33ef61b0b8a9fb556427a6c43a75de7b
ssdeep: 6144:owWXlvUMh0gk/VqFRaZvegKwog1sK4B8LW4WzRG9K:6qj/ZDnH/gzR7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184541266A0C8D5D6CA86093404938F37D3FBFA8531D02A47AF255FAFBD3E0532B52291
sha3_384: 53f513633c7a5e1015c424e1e5df43b678d7b770517135883258c9e80bdcd89544d2260a7a933d1f3a229f3b5c1c11ed
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Win32/Injector.EQZR also known as:

MicroWorld-eScanTrojan.GenericKD.48135728
FireEyeTrojan.GenericKD.48135728
McAfeeArtemis!2365543F0624
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058d8c21 )
BitDefenderTrojan.GenericKD.48135728
K7GWTrojan ( 0058d8c21 )
Cybereasonmalicious.f0624d
BitDefenderThetaGen:NN.ZedlaF.34182.bq4@aGCs1Kki
CyrenW32/Injector.ATR.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQZR
Paloaltogeneric.ml
ClamAVWin.Trojan.Midie-9937874-0
KasperskyHEUR:Trojan.Win32.Generic
AvastWin32:InjectorX-gen [Trj]
RisingTrojan.Injector!8.C4 (TFE:dGZlOgX/0TpnrhjOxg)
EmsisoftTrojan.GenericKD.48135728 (B)
McAfee-GW-EditionNSIS/ObfusInjector.h
SophosMal/Generic-S
APEXMalicious
AviraTR/Injector.csmhq
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.48135728
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ObfusInjector.R467391
ALYacTrojan.GenericKD.48135728
MalwarebytesTrojan.Injector.DL.Generic
IkarusTrojan.NSIS.Agent
FortinetW32/Injector.EQZR!tr
AVGWin32:InjectorX-gen [Trj]

How to remove Win32/Injector.EQZR?

Win32/Injector.EQZR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment