Trojan

Should I remove “Trojan.Agent.EWAY”?

Malware Removal

The Trojan.Agent.EWAY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EWAY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.EWAY?


File Info:

crc32: 353496E5
md5: 7cd1742ccc4825f94908744365330e08
name: upload_file
sha1: e402f4da98420b44442bf8feff0d4fa3075a375c
sha256: 003a6be25aed1e04592c3f6a153055b6c2e50f136315a079e99140d0f00c953a
sha512: 31f0d7baa5377e3ab0755aef2cc31200b72558abea14a69d9ac239fe4c586cbb9bdf5b53abd46877fc347c5377158d727c4c4ca0a82af4228c061cdc7e25991d
ssdeep: 6144:87v0APRNxu6+LJf484GOH2ELUF+CDcciNFd5lIj0O:IxeLJw8Z4LUF+CD5qd5K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Free to redistribute!
InternalName: cmdcmxcfg.exe
FileVersion: 1.0.0.1
CompanyName: Shaun Harrington
ProductName: CMDCMX
ProductVersion: 1.0.0.1
FileDescription: CMDCMX Configuration Application
OriginalFilename: cmdcmxcfg.exe
Translation: 0x0409 0x04e4

Trojan.Agent.EWAY also known as:

BkavW32.VobfusAgentHK.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EWAY
FireEyeGeneric.mg.7cd1742ccc4825f9
Qihoo-360Win32/Trojan.cfe
ALYacTrojan.Agent.Emotet
CylanceUnsafe
ZillyaTrojan.Emotet.Win32.28383
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusTrojan ( 0056dc831 )
BitDefenderTrojan.Agent.EWAY
K7GWTrojan ( 0056dc831 )
TrendMicroTROJ_GEN.R011C0DI720
BitDefenderThetaGen:NN.ZexaF.34216.vq0@a4Gwd6ji
CyrenW32/Kryptik.BWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HFZB
TrendMicro-HouseCallTROJ_GEN.R011C0DI720
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.gdnj
AlibabaTrojan:Win32/Emotet.b7aff160
NANO-AntivirusTrojan.Win32.Emotet.hucxwa
TencentMalware.Win32.Gencirc.10cdfdbe
Ad-AwareTrojan.Agent.EWAY
TACHYONTrojan/W32.Agent.348160.ALL
F-SecureTrojan.TR/Crypt.Agent.bqhnn
DrWebTrojan.DownLoader34.32251
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Emotet-CLZ
SophosTroj/Emotet-CLZ
APEXMalicious
JiangminTrojan.Banker.Emotet.oie
AviraTR/Crypt.Agent.bqhnn
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARK!MTB
ArcabitTrojan.Agent.EWAY
AhnLab-V3Trojan/Win32.Emotet.R350346
ZoneAlarmTrojan-Banker.Win32.Emotet.gdnj
GDataTrojan.Agent.EWAY
McAfeeEmotet-FSD!7CD1742CCC48
MAXmalware (ai score=87)
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.Agent
IkarusTrojan-Banker.Emotet
PandaTrj/Genetic.gen
RisingDownloader.Obfuse!8.105AD (TFE:6:qryoc0yxlYU)
FortinetW32/Kryptik.HFZB!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.106378932.susgen

How to remove Trojan.Agent.EWAY?

Trojan.Agent.EWAY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment