Trojan

Trojan.Agent.EIDY (file analysis)

Malware Removal

The Trojan.Agent.EIDY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EIDY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.EIDY?


File Info:

crc32: F64D4E65
md5: e4c2a573602e038e960005214ea4621e
name: exloader-18765c4.exe
sha1: 7e80d8e886043ae17be9f28d8cf4f4b86758aeed
sha256: eaf0df759928800847685091817abe4f317d61086c3df2d4d50658b67313ea43
sha512: bfd9987cf98d439e4e7a3c968ac277e8e338875912e680492281eabffcacf8444252ffb249fdd6cac90cd14575939071678bcec938db7f736ca6e4ed4dd260a8
ssdeep: 49152:l57a2p3uaChIMfNqGDNW9efzxMKa4MhJ+JNITlsfzW:37LuaoqkNW0r2hbfsX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) Paragon Software Group 1994-2008
InternalName: AudioBurner.exe
FileVersion: 9,0,0,0
CompanyName: Paragon Software Group
ProductName: Paragon Software Group SDK
ProductVersion: 9.0
FileDescription: Audio Burner Wizard
OriginalFilename: AudioBurner.exe
Translation: 0x0409 0x04e4

Trojan.Agent.EIDY also known as:

DrWebTrojan.DownLoader30.45745
MicroWorld-eScanTrojan.Agent.EIDY
FireEyeGeneric.mg.e4c2a573602e038e
McAfeeGenericR-RLU!E4C2A573602E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.Agent.EIDY
K7GWTrojan ( 0055c4b41 )
K7AntiVirusTrojan ( 0055c4b41 )
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DKU19
AvastWin32:AdwareX-gen [Adw]
GDataTrojan.Agent.EIDY
KasperskyHEUR:Trojan.Win32.Ekstak.vho
AlibabaTrojan:Win32/Ekstak.47eccdbf
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Kryptik.2465792
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
SophosTroj/Agent-BDBB
F-SecureTrojan.TR/Crypt.Agent.ubbxg
ZillyaTrojan.Kryptik.Win32.1862805
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Crypt
JiangminTrojan.Ekstak.aujn
WebrootW32.Malware.Gen
AviraTR/Crypt.Agent.ubbxg
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Ekstak.CF!MTB
ArcabitTrojan.Agent.EIDY
ZoneAlarmHEUR:Trojan.Win32.Ekstak.vho
AhnLab-V3Malware/Win32.Generic.C3592407
Acronissuspicious
VBA32BScope.Trojan.Ekstak
ALYacTrojan.Agent.EIDY
Ad-AwareTrojan.Agent.EIDY
MalwarebytesAdware.DownloadAssistant
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.GYUK
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.DYKG!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.66d

How to remove Trojan.Agent.EIDY?

Trojan.Agent.EIDY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment