Malware

Should I remove “Win32/Injector.ETKA”?

Malware Removal

The Win32/Injector.ETKA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ETKA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.ETKA?


File Info:

name: D628BC1A030B4DC648D2.mlw
path: /opt/CAPEv2/storage/binaries/6f1c2891717d860529f6603942c3a36eb018bcc94fe9421aa16342a590e8529b
crc32: 3A32608D
md5: d628bc1a030b4dc648d2f2817f0efe46
sha1: 5cbda467124a4008bb1522b096e4cd9afd958df7
sha256: 6f1c2891717d860529f6603942c3a36eb018bcc94fe9421aa16342a590e8529b
sha512: b08907b2e1ef1c33971ebc1729da9c20789f078afc480cd8f1e43c913013e87a34c2f96e49933eb92ddae557aa07890e8c51541b176a7e665a36bbbe3e4cb571
ssdeep: 12288:xfLxllCtmd/+Rn8EsDQbJXQ7a2vJIRSL54tRd7:xfLxmt4/+R8L0JgD/LSd7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBD426D8998AC046CA3D0D38CF98DBC62753A912001F397A6DFC6696127DDA7D0DA3CD
sha3_384: 2b993ec844f543675990caf5dfa6d7fabf02192ad269594fd5513d3ab3be7e5b98ffeffe161285fe12996b73dc8cad82
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:48

Version Info:

0: [No Data]

Win32/Injector.ETKA also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Loader.1550
CynetMalicious (score: 100)
FireEyeGeneric.mg.d628bc1a030b4dc6
SkyhighBehavesLike.Win32.Worm.jc
McAfeeArtemis!D628BC1A030B
MalwarebytesTrojan.Injector
BitDefenderTrojan.NSISX.Spy.Gen.24
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.wqW@aWUCpbki
VirITTrojan.Win32.GenusT.DTCM
ESET-NOD32a variant of Win32/Injector.ETKA
APEXMalicious
KasperskyHEUR:Trojan.Win32.Strab.gen
NANO-AntivirusTrojan.Win32.Strab.kcriij
MicroWorld-eScanTrojan.NSISX.Spy.Gen.24
RisingTrojan.Injector!8.C4 (TFE:5:DgRNnWGjHlD)
F-SecureTrojan.TR/Injector.tzvbh
VIPRETrojan.NSISX.Spy.Gen.24
TrendMicroTROJ_GEN.R002C0WJQ23
EmsisoftTrojan.NSISX.Spy.Gen.24 (B)
IkarusTrojan.Win32.Injector
AviraTR/Injector.tzvbh
Kingsoftmalware.kb.a.890
MicrosoftTrojan:Win32/Leonem
ArcabitTrojan.NSISX.Spy.Gen.24 [many]
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
GDataTrojan.NSISX.Spy.Gen.24
GoogleDetected
AhnLab-V3Trojan/Win.PWS.C4795854
VBA32BScope.Trojan.Injector
ALYacGen:Heur.Mint.Zard.55
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R06CH0DJK23
SentinelOneStatic AI – Suspicious PE
FortinetNSIS/Agent.DCAC!tr
AVGWin32:InjectorX-gen [Trj]
Cybereasonmalicious.7124a4
AvastWin32:InjectorX-gen [Trj]

How to remove Win32/Injector.ETKA?

Win32/Injector.ETKA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment