Trojan

Trojan.Agent.EWZV removal instruction

Malware Removal

The Trojan.Agent.EWZV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EWZV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Agent.EWZV?


File Info:

crc32: EAC61285
md5: c36c4ffe14617a8cc9cb7ceac4645fab
name: upload_file
sha1: b155fc2a6fbe9eb160030c23795aeb1716a06cd6
sha256: 1c9a1b4a35a5bf71b548689de1cbff59b820d8b8d929ff0f9c2da81d6bddc93c
sha512: 7aae5b00a06adce772989e18b8201c43e18c38ea630e5adb03de5f51f37299b9160cdfe613cfff67da5dc31cc2dc1fabcfe01c30e29329c5be37be5363879166
ssdeep: 12288:wMcacEq+U5RyKETLgS0bskxpVehVzmacEuh+e8:wkcZrW05ehVtcBt8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Tsukishima Monja Kkoboreya
FileVersion: 1.00
CompanyName: Hawaiian Style
ProductName: Tsukishima Monja Kkoboreya
ProductVersion: 1.00
FileDescription: AGBO Business Architecture S.L.
OriginalFilename: Tsukishima Monja Kkoboreya.exe

Trojan.Agent.EWZV also known as:

MicroWorld-eScanTrojan.Agent.EWZV
FireEyeGeneric.mg.c36c4ffe14617a8c
Qihoo-360Win32/Trojan.c25
ALYacTrojan.Agent.EWZV
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056f84b1 )
BitDefenderTrojan.Agent.EWZV
K7GWTrojan ( 0056f84b1 )
TrendMicroTROJ_GEN.R002C0DIR20
CyrenW32/VBKrypt.AOJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Vebzenpak.aaoj
AlibabaTrojan:Win32/Vebzenpak.08c58bcf
RisingTrojan.Kryptik!1.C606 (CLASSIC)
Ad-AwareTrojan.Agent.EWZV
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.izqjv
DrWebTrojan.DownLoader34.51669
InvinceaMal/Generic-S
McAfee-GW-EditionTrickbot-FSTA!C36C4FFE1461
EmsisoftTrojan.Agent.EWZV (B)
SentinelOneDFI – Suspicious PE
GDataTrojan.Agent.EWZV
JiangminTrojan.Vebzenpak.hrf
AviraTR/Kryptik.izqjv
Antiy-AVLTrojan/Win32.Vebzenpak
ZoneAlarmTrojan.Win32.Vebzenpak.aaoj
MicrosoftTrojan:Win32/EmotetCrypt.PEF!MTB
AhnLab-V3Trojan/Win32.Emotet.R352286
McAfeeTrickbot-FSTA!C36C4FFE1461
TACHYONTrojan/W32.VB-Vebzenpak.540672
MalwarebytesTrojan.MalPack.TRE
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ENKS
TrendMicro-HouseCallTROJ_GEN.R002C0DIR20
TencentMalware.Win32.Gencirc.10ce0625
MAXmalware (ai score=81)
FortinetPossibleThreat.ARN.H
BitDefenderThetaGen:NN.ZevbaF.34254.Hm0@a4Zd0Tck
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.107178510.susgen

How to remove Trojan.Agent.EWZV?

Trojan.Agent.EWZV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment