Trojan

Trojan.Agent.EWAU malicious file

Malware Removal

The Trojan.Agent.EWAU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EWAU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

How to determine Trojan.Agent.EWAU?


File Info:

crc32: 72DED946
md5: 789145fafcbe67d7a2f8cf289b01245e
name: upload_file
sha1: 1707863f32553dfac18e575196ce62e5ad861c08
sha256: 2ac4707a4fd61af734118e857f6156003b9e7fe6bc628e1845f31ceb52cae552
sha512: 8b275aca1fa36475c3cfb38c65b19c66785f2374d5e5c2e77e8cb984917fba5d04cb030650b291ce4bf2b9b624c417ea4fefb8ff6b04cc045729108a58388c94
ssdeep: 6144:9WIr7BmCNyXHhGVDfF6TREmvZmHzFxYClHg5U:4E7BmSkHEV56vvZmHzjlA5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Free to redistribute!
InternalName: cmdcmxcfg.exe
FileVersion: 1.0.0.1
CompanyName: Shaun Harrington
ProductName: CMDCMX
ProductVersion: 1.0.0.1
FileDescription: CMDCMX Configuration Application
OriginalFilename: cmdcmxcfg.exe
Translation: 0x0409 0x04e4

Trojan.Agent.EWAU also known as:

BkavW32.EmotetQKA.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EWAU
FireEyeTrojan.Agent.EWAU
CAT-QuickHealTrojanBanker.Emotet
ALYacTrojan.Agent.Emotet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056dc9c1 )
BitDefenderTrojan.Agent.EWAU
K7GWTrojan ( 0056dc9c1 )
TrendMicroTROJ_GEN.R011C0DI720
CyrenW32/Kryptik.BWJ.gen!Eldorado
SymantecPacked.Generic.554
ESET-NOD32a variant of Win32/Kryptik.HFZB
TrendMicro-HouseCallTROJ_GEN.R011C0DI720
Paloaltogeneric.ml
ClamAVWin.Malware.Emotet-9753021-0
KasperskyTrojan-Banker.Win32.Emotet.gdnb
AlibabaTrojan:Win32/Emotet.37f1488b
NANO-AntivirusTrojan.Win32.Emotet.hucsvi
AegisLabTrojan.Win32.Emotet.L!c
TencentMalware.Win32.Gencirc.10cdfe4d
Ad-AwareTrojan.Agent.EWAU
SophosTroj/Emotet-CLZ
F-SecureTrojan.TR/AD.Emotet.symag
DrWebTrojan.DownLoader34.32692
ZillyaTrojan.Emotet.Win32.28375
InvinceaMal/Generic-R + Troj/Emotet-CLZ
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
EmsisoftTrojan.Emotet (A)
APEXMalicious
JiangminTrojan.Banker.Emotet.oic
AviraTR/AD.Emotet.symag
MAXmalware (ai score=83)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARK!MTB
ArcabitTrojan.Agent.EWAU
AhnLab-V3Malware/Win32.Generic.C4192695
ZoneAlarmTrojan-Banker.Win32.Emotet.gdnb
GDataTrojan.Agent.EWAU
CynetMalicious (score: 85)
McAfeeEmotet-FSD!789145FAFCBE
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.Agent
RisingDownloader.Obfuse!8.105AD (TFE:6:qryoc0yxlYU)
IkarusTrojan-Banker.Emotet
FortinetW32/Emotet.2B27!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.c97

How to remove Trojan.Agent.EWAU?

Trojan.Agent.EWAU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment