Malware

What is “Win32/Injector.ERDQ”?

Malware Removal

The Win32/Injector.ERDQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ERDQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Win32/Injector.ERDQ?


File Info:

name: 393C580A147CEB59DFB9.mlw
path: /opt/CAPEv2/storage/binaries/74651dedba95ec668db7d4e545be66d575b7f3f7af03b3d5d91148f01db746e2
crc32: 1BE0F61F
md5: 393c580a147ceb59dfb9d92d36dd1aef
sha1: 46789892c49246f1291016e8a1972010e439fd08
sha256: 74651dedba95ec668db7d4e545be66d575b7f3f7af03b3d5d91148f01db746e2
sha512: 38cd6039e6dc4b2da48c4aa47f1e02dd8b1efa17494b7db5cc0efacc2e0e860cb424b37333eee4a43add3481b3ce224d0c3d2528793bd81f5677b851c56a7bd6
ssdeep: 3072:IWum2MgWZDPWI4YMIoII//pxMn/LjqazsfJrHgW9Im2M7WX:IfmRgoPW33ISRxuNsfJrXImR72
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A447C73F289193AF462C8BC9621A68E58D17C7140519B19BEC1BA14E2312DF735BF3B
sha3_384: d71eb7655cc4cd74ddc54d6482d251d3456e1e919a8b1d43cefda91690cf5ee10e94edc5c7806c2dd6542b4713722448
ep_bytes: 6874714000e8eeffffff000000000000
timestamp: 2016-02-21 16:40:57

Version Info:

Translation: 0x0409 0x04b0
FileDescription: CorelDraw Converter Professional
LegalCopyright: Copyright © CorelDraw AG
LegalTrademarks: Copyright © CorelDraw AG
ProductName: HAANDGERN
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ufremkomme
OriginalFilename: ufremkomme.exe

Win32/Injector.ERDQ also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.qm1@UKtOkgki
FireEyeGeneric.mg.393c580a147ceb59
ALYacTrojan.SmokeLoader
ZillyaTrojan.Injector.Win32.1507731
SangforDropper.Win32.Agent.Vmxi
K7AntiVirusTrojan ( 0058ea111 )
AlibabaTrojanDropper:Win32/Dapato.89bbcc94
K7GWTrojan ( 0058ea111 )
Cybereasonmalicious.a147ce
BitDefenderThetaGen:NN.ZevbaF.34682.qm1@aKtOkgki
CyrenW32/VB.VG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ERDQ
TrendMicro-HouseCallTROJ_GEN.R002C0PBL22
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Dapato.qyrc
BitDefenderGen:Heur.PonyStealer.qm1@UKtOkgki
NANO-AntivirusTrojan.Win32.Dapato.jmpmkr
CynetMalicious (score: 100)
APEXMalicious
TencentWin32.Trojan-Dropper.Dapato.Mqil
Ad-AwareGen:Heur.PonyStealer.qm1@UKtOkgki
EmsisoftTrojan.Injector (A)
ComodoMalware@#dutwz4jtp04p
VIPREGen:Heur.PonyStealer.qm1@UKtOkgki
TrendMicroTROJ_GEN.R002C0PBL22
McAfee-GW-EditionGuLoader-FDBM!393C580A147C
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataGen:Heur.PonyStealer.qm1@UKtOkgki
JiangminTrojanDropper.Dapato.adgx
AviraHEUR/AGEN.1248053
MAXmalware (ai score=100)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.PonyStealer.ED8A18
ZoneAlarmTrojan-Dropper.Win32.Dapato.qyrc
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
McAfeeGuLoader-FDBM!393C580A147C
VBA32BScope.Backdoor.Androm
CylanceUnsafe
AvastWin32:DangerousSig [Trj]
RisingTrojan.Injector!1.B459 (CLASSIC)
FortinetW32/PossibleThreat
AVGWin32:DangerousSig [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.ERDQ?

Win32/Injector.ERDQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment