Trojan

Trojan.Agent.EYEE removal guide

Malware Removal

The Trojan.Agent.EYEE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EYEE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Agent.EYEE?


File Info:

crc32: 636E8DDF
md5: 32ccace204c341120b7d65fac94a06c3
name: 32CCACE204C341120B7D65FAC94A06C3.mlw
sha1: c2c8f50f0a236f70b26ebcf76107804710574fc7
sha256: bcaf7a9fe3737ebac1c1a5a0038e1ce2bd65de27a99144f525df42935ea37e2c
sha512: 6b3c39636df89af152cc63efd1f54638238c4a4289bd1698b31555f79d6951184d547719c2ff9ec785832a0079df5f01c5c82d1c1ee4c7d1d9753b0a367a9b62
ssdeep: 3072:iNQzyIMwIteLJDBK58kkCEeaYzTPH8iLYXYt5z:iNUMwIwL+NkCZa6Pc/YP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Yonatan, 2001-2002
InternalName: Yonatan's Screen of Death
FileVersion: 1.1
CompanyName: Yonatan
Comments: Yonatan's Screen of Death, for Windows 95, Windows 98 and Windows ME
ProductName: YSOD
ProductVersion: 1.1
FileDescription: Yonatan's Screen of Death
OriginalFilename: YSOD.exe
Translation: 0x0409 0x04b0

Trojan.Agent.EYEE also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYEE
FireEyeGeneric.mg.32ccace204c34112
CAT-QuickHealTrojan.EmotetcryptRI.S16566676
ALYacTrojan.Agent.EYEE
CylanceUnsafe
K7AntiVirusTrojan ( 005729521 )
BitDefenderTrojan.Agent.EYEE
K7GWTrojan ( 005729521 )
Cybereasonmalicious.f0a236
CyrenW32/Emotet.AVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Generic-9783957-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.vho
NANO-AntivirusTrojan.Win32.Emotet.iaujfq
RisingTrojan.Kryptik!1.CE17 (CLASSIC)
Ad-AwareTrojan.Agent.EYEE
TACHYONTrojan/W32.Agent.135168.CVO
EmsisoftTrojan.Emotet (A)
DrWebTrojan.Emotet.1044
InvinceaMal/Agent-AVJ
McAfee-GW-EditionTrickbot-FTBA!32CCACE204C3
SophosMal/Agent-AVJ
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.pbt
WebrootW32.Trojan.Trickbot
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
GridinsoftPUP.Win32.Fuerboos.ka!n
ArcabitTrojan.Agent.EYEE
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.vho
GDataTrojan.Agent.EYEE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R353971
McAfeeTrickbot-FTBA!32CCACE204C3
MAXmalware (ai score=86)
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HGZT
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HGZT!tr
BitDefenderThetaGen:NN.ZexaF.34590.iC0@aWHIiKli
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Agent.EYEE?

Trojan.Agent.EYEE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment