Trojan

MemScan:Trojan.Agent.EHHW information

Malware Removal

The MemScan:Trojan.Agent.EHHW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What MemScan:Trojan.Agent.EHHW virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine MemScan:Trojan.Agent.EHHW?


File Info:

crc32: A872A3EE
md5: 29bfb9ca1f63cdc8709678e9dd7e4aec
name: 2062225.jpg
sha1: ee231a9b19bd70bcbc4306b76f8253548ddd2b8e
sha256: a1b489732441eae086ef6a4c0a7cbf9ee5d933183551460391c2b91906cb285c
sha512: c63759c3814be188b1499f0821206e157bcbcf793015919b1c8a458b18769b036f90283c2fe598b1e8c797af5d238d19a73a766cecf71342773f1d72abdf7f58
ssdeep: 49152:CEuN2wWqiww2HcMCY7BDOVHLVfT8bbhzTf5erzX9Hb7oNMeHE5Fso3W:CEuNbWqi67BDOVHLVfT8bbhzTf5erzX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MemScan:Trojan.Agent.EHHW also known as:

BkavW32.GenericBinderLnr.Trojan
MicroWorld-eScanMemScan:Trojan.Agent.EHHW
CMCHackTool.Win32.Binder!O
CAT-QuickHealVirTool.Vbinder.CO5
McAfeeTrojan-FDDZ!29BFB9CA1F63
MalwarebytesHackTool.Binder
SUPERAntiSpywareTrojan.Agent/Gen-Binder
K7AntiVirusTrojan ( 004babd11 )
AlibabaHackTool:Win32/Binder.44d01671
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.a1f63c
ArcabitTrojan.Agent.EHHW
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaCO3.32250.LvW@aS0lkBjG
CyrenW32/Backdoor.FVDJ-1096
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AGBZ
BaiduWin32.Trojan-Dropper.Binder.m
APEXMalicious
ClamAVWin.Trojan.Binder-6
KasperskyHackTool.Win32.Binder.bs
BitDefenderMemScan:Trojan.Agent.EHHW
Paloaltogeneric.ml
AegisLabHacktool.Win32.Binder.lo77
Ad-AwareMemScan:Trojan.Agent.EHHW
EmsisoftGen:Variant.Binder.1 (B)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
F-SecureHeuristic.HEUR/AGEN.1026512
DrWebTrojan.MulDrop2.39589
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.29bfb9ca1f63cdc8
SophosMal/Fareit-V
SentinelOneDFI – Malicious PE
F-ProtW32/Backdoor2.HKXU
JiangminHackTool.Binder.bh
AviraHEUR/AGEN.1026512
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftVirTool:Win32/Vbinder.CO
Endgamemalicious (high confidence)
ViRobotTrojan.Win32.A.Swisyn.49120
ZoneAlarmHackTool.Win32.Binder.bs
GDataWin32.Trojan.Binder.A
AhnLab-V3HackTool/Win32.Vbinder.R12127
Acronissuspicious
VBA32Binder.Celesty
ALYacMemScan:Trojan.Agent.EHHW
CylanceUnsafe
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexHackTool.Binder!IMtdREcP3/k
IkarusTrojan.Win32.Dorv
MaxSecureHackTool.W32.Binder.bs
FortinetW32/Dropper.NBH!tr
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Hacktool.4af

How to remove MemScan:Trojan.Agent.EHHW?

MemScan:Trojan.Agent.EHHW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment