Trojan

Should I remove “Trojan.Agent.EYFR”?

Malware Removal

The Trojan.Agent.EYFR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EYFR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Anomalous binary characteristics

How to determine Trojan.Agent.EYFR?


File Info:

crc32: 3DA3A4B6
md5: ff3b9c8419287ee2ff7c617280917a3e
name: D1JXXRaPs0mg.exe
sha1: e62dd95225d9e530983b57069570fa733c9915fc
sha256: 501dcc9e5bd755038c62190cc938c23c99e55ca42d8d3eca540b1c18e55921d0
sha512: 9e94474bd678f0aa6bf7bad6a62b02451752f4dce69ef060bd38b198ae9caa239f875466a8f2398cd8d585cb8c00219f0e2b4ea7b64d14ce189cd1bdb92f0992
ssdeep: 12288:zXsObAC+H3bd40FM1OpzFt4t/tltJt004m6E0p:zzMC+HTFM1OpzhnF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: CCircFileDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CCircFileDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: CCircFileDemo MFC Application
OriginalFilename: CCircFileDemo.EXE
Translation: 0x0409 0x04b0

Trojan.Agent.EYFR also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYFR
FireEyeGeneric.mg.ff3b9c8419287ee2
ALYacTrojan.Agent.Emotet
BitDefenderTrojan.Agent.EYFR
TrendMicroTrojanSpy.Win32.EMOTET.SMU.hp
CyrenW32/Kryptik.APD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Emotetu-9784444-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
AlibabaTrojan:Win32/EmotetCrypt.619e2ba1
AegisLabTrojan.Win32.Emotet.L!c
Ad-AwareTrojan.Agent.EYFR
SophosTroj/Emotet-CSI
F-SecureTrojan.TR/Crypt.Agent.xuuji
DrWebTrojan.Emotet.1046
InvinceaTroj/Emotet-CSI
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
WebrootW32.Trojan.Emotet
AviraTR/Crypt.Agent.xuuji
MAXmalware (ai score=88)
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.Agent.EYFR
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataTrojan.Agent.EYFR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R354300
Acronissuspicious
McAfeeEmotet-FSF!FF3B9C841928
TACHYONTrojan/W32.Agent.428032.UB
VBA32Trojan.Emotet
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HHBE
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMU.hp
TencentWin32.Trojan-banker.Emotet.Efax
FortinetW32/BankerX.5CC7!tr
BitDefenderThetaGen:NN.ZexaF.34590.Au0@aKkhoGki
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.adb

How to remove Trojan.Agent.EYFR?

Trojan.Agent.EYFR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment