Trojan

AIT:Trojan.Agent.EGMR removal guide

Malware Removal

The AIT:Trojan.Agent.EGMR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Agent.EGMR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine AIT:Trojan.Agent.EGMR?


File Info:

name: D10646A315EDAFF2E179.mlw
path: /opt/CAPEv2/storage/binaries/a84d3e094df0aa3b0fb61657457ae5676fadd0727824be0d139bb98bf54be923
crc32: EFC82A0E
md5: d10646a315edaff2e179a716ca82b06a
sha1: 095aeef630b48d9d3cbd332a4925aeeafcbac352
sha256: a84d3e094df0aa3b0fb61657457ae5676fadd0727824be0d139bb98bf54be923
sha512: 3940bad777213edf2738deab572eaed08a2d1364d47ae88d00a3581cf17a8b34fbf3a5b982698062f38eef2986636f4f7ac132bc9c7bff983f8dadf3d018ff72
ssdeep: 24576:mu6Jx3O0c+JQZ+XC0kGso/banhblk9XCO5WYo:oI0c+GCvkGsUbau0Yo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18245CF63B1CDC2A1CE2651B3BF19B7526F3F7C750670841733983E69AE61162122DBA3
sha3_384: 1ac49537c85f36cc291497ca244e6f271e50597c45c5cf003dc474a333e907b13aeefff73df5cf83eb10cde0257b97f9
ep_bytes: e8b5d00000e97ffeffffcccccccccccc
timestamp: 2019-10-29 08:10:58

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Agent.EGMR also known as:

LionicTrojan.Win32.Azorult.i!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.9221
MicroWorld-eScanAIT:Trojan.Agent.EGMR
FireEyeGeneric.mg.d10646a315edaff2
ALYacAIT:Trojan.Agent.EGMR
CylanceUnsafe
K7AntiVirusTrojan ( 0055d15b1 )
AlibabaTrojan:Win32/AutoItGen.107
K7GWTrojan ( 0055d15b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/AutoIt.OW.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Packed.AutoIt.TT
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMP
KasperskyTrojan-PSW.Win32.Azorult.aecr
BitDefenderAIT:Trojan.Agent.EGMR
NANO-AntivirusTrojan.Script.Vbs-heuristic.druvzi
AvastAutoIt:Injector-JV [Trj]
TencentWin32.Trojan.Falsesign.Wmsc
EmsisoftAIT:Trojan.Agent.EGMR (B)
TrendMicroBackdoor.AutoIt.BLADABINDI.SMP
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
SophosML/PE-A + Mal/AuItInj-A
IkarusTrojan.RAT.NanoCore
AviraHEUR/AGEN.1245421
GridinsoftRansom.Win32.AzorUlt.sa
MicrosoftTrojan:Win32/Predator.BC!MTB
ZoneAlarmTrojan-PSW.Win32.Azorult.aecr
GDataAIT:Trojan.Agent.EGMR
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoinj03.Exp
McAfeeArtemis!D10646A315ED
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.AutoIt
APEXMalicious
RisingTrojan.Obfus/Autoit!1.BD7E (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Agent.AAJ!tr
AVGAutoIt:Injector-JV [Trj]
Cybereasonmalicious.315eda
PandaTrj/CI.A

How to remove AIT:Trojan.Agent.EGMR?

AIT:Trojan.Agent.EGMR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment