Trojan

Should I remove “Trojan.Agent.ECLZ”?

Malware Removal

The Trojan.Agent.ECLZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.ECLZ virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Agent.ECLZ?


File Info:

name: 2F85CB79894AD15FE927.mlw
path: /opt/CAPEv2/storage/binaries/e3bb00917d99adbf6de2e84c0a0cfbc026e6d22ba86de8db8a41fb8a899f85cb
crc32: 893B2A63
md5: 2f85cb79894ad15fe92710fe77848e5b
sha1: f8f7a3127da7e428affe6d66ad9868976ff458b3
sha256: e3bb00917d99adbf6de2e84c0a0cfbc026e6d22ba86de8db8a41fb8a899f85cb
sha512: 46117342aa4448e678be16c82dc3ad0432a472fd7aa7400903429f53e61f8d19204a1ebb7aadb3aa5097bd97e031b9f30bfbd32bedc0d9bcba7e39741f87c773
ssdeep: 768:L6qh5nWLQF/NwwC/7gfS50BQifgvYnbcuyD7U:L665WLiVwtz4pfgvYnouy8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE134C997A8A2956E0C900381C15E52B6054AF0821EFCF93FDD566BBDD8F7B428186F3
sha3_384: eee057228993b0770cbfc0a14ae452a7e0d603bf766d5a24cf02dd8323df0dfabfa1f53e7a8bf797232170e0447626a6
ep_bytes: 60be152041008dbeebeffeff5789e58d
timestamp: 2006-03-02 17:50:37

Version Info:

0: [No Data]

Trojan.Agent.ECLZ also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.Agent.tpn3
MicroWorld-eScanTrojan.Agent.ECLZ
FireEyeGeneric.mg.2f85cb79894ad15f
McAfeeGenericRXKN-BX!2F85CB79894A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001f98061 )
AlibabaWorm:Win32/Sfone.6949a3e9
K7GWTrojan ( 001f98061 )
Cybereasonmalicious.9894ad
CyrenW32/Backdoor.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.BEGYOIC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Eclz-9953021-0
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderTrojan.Agent.ECLZ
AvastWin32:Trojan-gen
TencentTrojan.Win32.Sdum.hc
Ad-AwareTrojan.Agent.ECLZ
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Agent.ECLZ
TrendMicroTROJ_GEN.R002C0DH822
McAfee-GW-EditionBehavesLike.Win32.Sodinokibi.pt
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.ECLZ (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.ECLZ
JiangminTrojan.Multi.jtl
GoogleDetected
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=87)
ArcabitTrojan.Agent.ECLZ
ViRobotTrojan.Win32.Z.Sfone.43008.WV
MicrosoftWorm:Win32/Sfone
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Agent.R339926
BitDefenderThetaAI:Packer.D9CB31D61B
ALYacTrojan.Agent.ECLZ
MalwarebytesGeneric.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0DH822
RisingWorm.Sfone!8.1B7 (TFE:1:CXDyp1xtUFU)
IkarusWorm.Win32.Sfone
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Crypt.ULPM!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.ECLZ?

Trojan.Agent.ECLZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment