Malware

Should I remove “EvilEPL.1”?

Malware Removal

The EvilEPL.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What EvilEPL.1 virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Clears web history

How to determine EvilEPL.1?


File Info:

crc32: BC003461
md5: 96b89dd4dab10e35b070b66aa7cefb17
name: 96B89DD4DAB10E35B070B66AA7CEFB17.mlw
sha1: 26631ccff2984ec13c7d407054451d54f8f943bd
sha256: c0edc37c06ef330654feabce5946f2e84a8bbf938613cfc573de826290062a37
sha512: 6d379bd4f844740d561d1d33f49ca3c6e30cbfb1ef1576eaf44807969329ce7bf4c5ce55b786c2cd00f8f6cd93426ae707ce8b9a2f5a5bb27d466bb24d1205d5
ssdeep: 24576:p9DnZIJqf25xqZyqmcGznIHf6/0xsd2PJu7UzcFtJNjkvJspb4h11YZrEAY:p1ZIJq250Zy5HIHiZd2PM7UwvJNw2pqb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

EvilEPL.1 also known as:

BkavW32.FlyStudioTn.Heur
TotalDefenseWin32/Nuj.B!generic
MicroWorld-eScanGen:Variant.EvilEPL.1
CAT-QuickHealBackdoor.FlyAgent.F
McAfeeW32/Autorun.worm.bx
K7AntiVirusBackdoor ( 04c544dc1 )
K7GWBackdoor ( 04c544dc1 )
NANO-AntivirusTrojan.Win32.FlyStudio.dbcrxo
F-ProtW32/Nuj.A.gen!Eldorado
SymantecPacked.Generic.244
NormanFlyAgent.CX
TrendMicro-HouseCallWORM_AUTORUN.SMW
AvastWin32:EvilEPL [Cryp]
ClamAVWorm.FlyStudio-37
KasperskyTrojan-Downloader.Win32.FlyStudio.ip
BitDefenderGen:Variant.EvilEPL.1
AgnitumTrojan.ATRAPS!EvBjYpT26uo
SUPERAntiSpywareTrojan.Agent/Gen-XPFraud
TencentTrojan.Win32.FakeFolder.b
Ad-AwareGen:Variant.EvilEPL.1
SophosMal/EncPk-NB
ComodoTrojWare.Win32.Agent.btho
F-SecureTrojan-Dropper:W32/Peed.gen!A
DrWebTrojan.Siggen5.3303
VIPRETrojan.Win32.Autorun.dm (v)
AntiVirTR/ATRAPS.Gen2
TrendMicroWORM_AUTORUN.SMW
McAfee-GW-EditionW32/Autorun.worm.bx
EmsisoftGen:Variant.EvilEPL.1 (B)
ESET-NOD32Win32/Packed.FlyStudio.O.Gen
KingsoftWin32.TrojDownloader.FlyStudio.(kcloud)
JiangminTrojanDownloader.FlyStudio.sq
MicrosoftBackdoor:Win32/FlyAgent.F
GDataGen:Variant.EvilEPL.1
CommtouchW32/Nuj.A.gen!Eldorado
AhnLab-V3Win32/Flystudio.worm.Gen
PandaTrj/Flystudio.E
RisingPE:Worm.Win32.FakeFolder.cl!1075355280
IkarusTrojan.Win32.FlyStudio
FortinetW32/PckdFlyStudio.gen
AVGWin32/Heur
Baidu-InternationalTrojan.Win32.FlyStudio.arQ
Qihoo-360Win32/Trojan.Downloader.3e7

How to remove EvilEPL.1?

EvilEPL.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment