Trojan

Should I remove “Trojan.Agent.EKQZ (B)”?

Malware Removal

The Trojan.Agent.EKQZ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EKQZ (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

www.myexternalip.com
redirector.gvt1.com
r5—sn-4g5edne7.gvt1.com

How to determine Trojan.Agent.EKQZ (B)?


File Info:

crc32: 0AD10B4E
md5: 6e985b3c93d663e6783694a0e16c83bd
name: mini.png
sha1: a22745dbef12e6a83be72430a79f75f88f8c3dd1
sha256: 18105c82a558ff67d38b6ea60fbd86cf718086d48e251f4c7e21dd36c75937a4
sha512: 4e1bd8c7c5ad39a559d405981b6c0dcd4d5a03b8dfdbc63005cccaac7f97525677767eda7a3ce16819092662595e43ec9421dee4d16bc490156e50af6f76743d
ssdeep: 6144:OL3DL6Scw+I/6jUDysMhj6AnjQr3DHYlbtUnQrvIdO74oA7oTkXVNaj3:o6Scw+g6qysMhdjQKbtUQ7IirLTeAj3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: bsOctButton
FileVersion: 2.0.0.24
CompanyName: Dp look
ProductName: BadSoft bsOctControls
ProductVersion: 2.0.0.24
FileDescription: Vhatsapp dp for Stylish boys Images
OriginalFilename: bsOctButton.exe

Trojan.Agent.EKQZ (B) also known as:

MicroWorld-eScanTrojan.Agent.EKQZ
FireEyeGeneric.mg.6e985b3c93d663e6
Qihoo-360HEUR/QVM03.0.DDB3.Malware.Gen
McAfeeGenericRXAA-AA!6E985B3C93D6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.Agent.EKQZ
Cybereasonmalicious.bef12e
APEXMalicious
GDataTrojan.Agent.EKQZ
KasperskyTrojan.Win32.Mansabo.edf
RisingTrojan.Trickbot!8.E313 (C64:YzY0OijDw/ETnmEY)
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.EKQZ (B)
F-SecureTrojan.TR/AD.TrickBot.qkmjv
Invinceaheuristic
Trapminemalicious.moderate.ml.score
WebrootW32.Trojan.Trickbot
AviraTR/AD.TrickBot.qkmjv
MAXmalware (ai score=87)
ArcabitTrojan.Agent.EKQZ
ZoneAlarmTrojan.Win32.Mansabo.edf
AhnLab-V3Trojan/Win32.Trickbot.C3974822
Ad-AwareTrojan.Agent.EKQZ
PandaTrj/Emotet.A
ESET-NOD32a variant of Win32/Injector.EKFL
FortinetW32/GenKryptik.ECFC!tr
BitDefenderThetaGen:NN.ZevbaF.34084.Pm1@aKVb!Ifm
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Agent.EKQZ (B)?

Trojan.Agent.EKQZ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment