Malware

Win32/Injector.EQZZ removal tips

Malware Removal

The Win32/Injector.EQZZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQZZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • CAPE detected the Loki malware family
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system

How to determine Win32/Injector.EQZZ?


File Info:

name: 8E4C6F6D075DDE89982D.mlw
path: /opt/CAPEv2/storage/binaries/d16f89c837232783bc9047364818714d786ba3dd382f62bcbe77ac416f4d4bda
crc32: 589FFA4F
md5: 8e4c6f6d075dde89982dbde75f41f811
sha1: db8f6046bd1b27635ca51df95cf1a6c5a4b69356
sha256: d16f89c837232783bc9047364818714d786ba3dd382f62bcbe77ac416f4d4bda
sha512: 8a9c9811afd608b57cdd16da6f71a37174c12c55967e0befbb7d955f60cb93dd28ba5cfffd5c2cf40371aa6196ee2ff4ebb07d7d346215a409a42f490f83356d
ssdeep: 6144:owKzilKDznpoBa5gtB+VWMEnIYFLihgFW6ZGwS6wNni:Qio3nAtJMEIYFLsLZi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B34122571E48977D15749770C93A3BAC3FE5B102712018B6F942FEFA9122234E661EB
sha3_384: 8353060d2492be6b1674266ba73ab414de91f288ce044250a9bee276fd6ea41f99d44c0a9607485592c61bd201755523
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Win32/Injector.EQZZ also known as:

LionicTrojan.Multi.Generic.4!c
DrWebTrojan.Siggen16.38300
MicroWorld-eScanTrojan.GenericKD.48157676
FireEyeTrojan.GenericKD.48157676
ALYacTrojan.GenericKD.48157676
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058d97a1 )
AlibabaBackdoor:Win32/SpyNoon.c6ec3a46
K7GWTrojan ( 0058d97a1 )
Cybereasonmalicious.d075dd
BitDefenderThetaGen:NN.ZedlaF.34182.bq4@aSfhXSci
CyrenW32/Injector.ATR.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EQZZ
TrendMicro-HouseCallTROJ_FRS.VSNTAS22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.48157676
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
AvastWin32:PWSX-gen [Trj]
TencentWin32.Backdoor.Androm.Eckq
Ad-AwareTrojan.GenericKD.48157676
EmsisoftTrojan.GenericKD.48157676 (B)
TrendMicroTROJ_FRS.VSNTAS22
McAfee-GW-EditionRDN/Generic.grp
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataWin32.Trojan-Stealer.LokiBot.ULYMON
WebrootW32.Trojan.Risis.1
AviraTR/AD.LokiBot.exrsj
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2DED3EC
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Casdet!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ObfusInjector.R467391
McAfeeArtemis!8E4C6F6D075D
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.FL
APEXMalicious
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.EQZR!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.EQZZ?

Win32/Injector.EQZZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment