Malware

Win32/Injector.ERBE removal tips

Malware Removal

The Win32/Injector.ERBE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ERBE virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Win32/Injector.ERBE?


File Info:

name: D6890733FE03DA5AF7AC.mlw
path: /opt/CAPEv2/storage/binaries/76b1c5936c96c524d26fc898dfef7b885a3689631093ceab74fe45228a5cf4b4
crc32: 6369AC1B
md5: d6890733fe03da5af7acb3af9d9414f0
sha1: 160a612e0135b9763bbe6a2b0dfa31c990a7c5eb
sha256: 76b1c5936c96c524d26fc898dfef7b885a3689631093ceab74fe45228a5cf4b4
sha512: 02b1efaeb49e00e92156190fc574680ccd61982788700b4bbf04a3a0770e45d44b67d571ee4197af1638a46501eed9519780293e068efb56558b6aaa4a5c0b06
ssdeep: 6144:owE/r2v57xpmEPEsgCMt/loK7aWg9rgCiIjRGZufE1Za8x7J0icCF16lmxsASgVm:g/SxtZEsugKzruMisLH9x0FAe/K4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1A42318F6C4885BEC8C86F4CE7AA7D6E3B9BF00475543230784AE69243D1A25F1FE94
sha3_384: e3be3cb536a1352783ceac3f950c9d150b847195f825cf77cf8408b4174a580bb3b037e2ead31d6fa43a14a80e87ecb2
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Win32/Injector.ERBE also known as:

LionicTrojan.Win32.BypassUAC.4!c
MicroWorld-eScanTrojan.Risis.1.Gen
FireEyeTrojan.Risis.1.Gen
McAfeeArtemis!D6890733FE03
CylanceUnsafe
SangforTrojan.Win32.BypassUAC.gen
K7AntiVirusTrojan ( 0058df101 )
AlibabaTrojan:Win32/BypassUAC.0facde28
K7GWTrojan ( 0058df101 )
Cybereasonmalicious.3fe03d
CyrenW32/Injector.ATZ.gen!Eldorado
SymantecPacked.NSISPacker!g10
ESET-NOD32a variant of Win32/Injector.ERBE
TrendMicro-HouseCallTROJ_GEN.R002H06B422
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Risis.1.Gen
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Injector!8.C4 (CLOUD)
EmsisoftTrojan.Risis.1.Gen (B)
F-SecureTrojan.TR/Injector.hfobn
DrWebTrojan.Inject4.25235
TrendMicroTROJ_GEN.R002C0DB522
McAfee-GW-EditionNSIS/ObfusInjector.h
SophosMal/Generic-S
APEXMalicious
GDataWin32.Backdoor.Remcos.N0734Z
AviraTR/Injector.ynitb
MAXmalware (ai score=88)
ArcabitZum.Androm.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/SpyNoon.PDL!MTB
SentinelOneStatic AI – Suspicious PE
AhnLab-V3Trojan/Win.ObfusInjector.R467391
MalwarebytesTrojan.Injector
IkarusTrojan.Win32.Injector
FortinetW32/Injector.ERAJ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Win32/Injector.ERBE?

Win32/Injector.ERBE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment