Malware

Win32/Injector.EUK removal

Malware Removal

The Win32/Injector.EUK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EUK virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Win32/Injector.EUK?


File Info:

name: F0171677CBA644A6A72D.mlw
path: /opt/CAPEv2/storage/binaries/00b9422f0a3b1061c88c17bede636b78b2b5b9ca6f6753350940fd3365d1d558
crc32: E00ED18D
md5: f0171677cba644a6a72d9efdb9a32da0
sha1: cfee32fad009f6d5878da4299f3f61e20bfb7a43
sha256: 00b9422f0a3b1061c88c17bede636b78b2b5b9ca6f6753350940fd3365d1d558
sha512: cc61a1955fdea32d8c375a13519c65cdacbbe72c0d9a98b5c77938c102e4d27223e06070cf573596c4125e13d04e19c15576beebdb752b95425b8f3419c2ee4b
ssdeep: 384:h4Bo/FWcoPAMQ2zbijzTHZA7EMmsozHulisYpEO/n/XfmKctnqlfKP:h4BCY/LG/KYwozHufYpfn/v3lfy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T140135B03BD848033EAA583B89DFE6A7303BDE8204FA553D3F791524D99119D52931B9F
sha3_384: 5e54fc25a85aab859d86f100a135a21b2b9414dbb1c7b5384a83781e0a2e415f3423529e4f2fe4e5e2911e7a87072e4d
ep_bytes: 83ec1cc7042401000000ff1548d14000
timestamp: 2014-08-31 15:00:07

Version Info:

0: [No Data]

Win32/Injector.EUK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ProcessHijack.cGW@a83wNdj
FireEyeGeneric.mg.f0171677cba644a6
ALYacGen:Trojan.ProcessHijack.cGW@a83wNdj
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1551688
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/Injector.072b20f1
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.7cba64
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EUK
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ProcessHijack.cGW@a83wNdj
NANO-AntivirusTrojan.Win32.EUK.dekwul
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Generic.Dypj
Ad-AwareGen:Trojan.ProcessHijack.cGW@a83wNdj
ComodoMalware@#1m6jgxffffgoo
BaiduWin32.Worm.Autorun.bm
VIPREGen:Trojan.ProcessHijack.cGW@a83wNdj
TrendMicroTROJ_GEN.R002C0WFR22
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ProcessHijack.cGW@a83wNdj
JiangminTrojan.Generic.ayexk
AviraHEUR/AGEN.1231795
Antiy-AVLTrojan/Generic.ASMalwS.3303
ViRobotTrojan.Win32.Z.Processhijack.41984
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
McAfeeArtemis!F0171677CBA6
MAXmalware (ai score=86)
VBA32BScope.Trojan.Inject
TrendMicro-HouseCallTROJ_GEN.R002C0WFR22
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.Injector
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Dorkbot.AS!tr
AVGFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/Injector.EUK?

Win32/Injector.EUK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment