Trojan

Trojan.Agent.EIQI (B) information

Malware Removal

The Trojan.Agent.EIQI (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EIQI (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Trojan.Agent.EIQI (B)?


File Info:

crc32: 06580D1E
md5: a90d5fc3813407f23249257a0b1797ae
name: bestboby.exe
sha1: c40d13be865728d0926ab72e97d6161ee13e6a83
sha256: e3af5ad14c59be579ef3de89cf9d918418c533b04f7e4208f541c6fba571b657
sha512: f42ce87b979162512e823bae75327db2301c7ed0d2d34a70cf408285c6699904923cd28d577af7b0fed94a384bfa78cf587e37bf17536200079f40d3f177ac05
ssdeep: 24576:l9nNAqFPwnHkMfhpMWvXMGf8jjY7kI3zBIjnS2k:PyWGEM1MGkBTSB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.EIQI (B) also known as:

MicroWorld-eScanTrojan.Agent.EIQI
FireEyeGeneric.mg.a90d5fc3813407f2
McAfeeFareit-FQP!A90D5FC38134
CylanceUnsafe
AegisLabTrojan.Win32.Kryptik.4!c
SangforMalware
K7AntiVirusTrojan ( 0055cb681 )
BitDefenderTrojan.Agent.EIQI
K7GWTrojan ( 0055cb681 )
Cybereasonmalicious.e86572
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
F-ProtW32/Injector.IPP
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.Agent.EIQI
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/GenKryptik.0dcdce44
NANO-AntivirusTrojan.Win32.Inject3.gkizdd
ViRobotTrojan.Win32.Z.Injector.1274880
RisingTrojan.GenKryptik!8.AA55 (TFE:5:Mgpj23775RE)
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.EIQI (B)
F-SecureTrojan.TR/Injector.qzrei
DrWebTrojan.Inject3.31576
ZillyaTrojan.Injector.Win32.671153
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.th
SophosMal/Generic-S
IkarusTrojan.Inject
CyrenW32/Injector.PCTK-0655
JiangminTrojan.Kryptik.zq
AviraTR/Injector.qzrei
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Agent.EIQI
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacTrojan.Agent.Wacatac
Ad-AwareTrojan.Agent.EIQI
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.EJKF
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
FortinetW32/Injector.DZGI!tr
BitDefenderThetaGen:NN.ZelphiF.32519.nHW@aS@rwshi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.7ad

How to remove Trojan.Agent.EIQI (B)?

Trojan.Agent.EIQI (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment