Trojan

About “Trojan.Agent.EZKD” infection

Malware Removal

The Trojan.Agent.EZKD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EZKD virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Agent.EZKD?


File Info:

crc32: 633E69BF
md5: 63f97fc0e953ed9765117e661e666941
name: 63F97FC0E953ED9765117E661E666941.mlw
sha1: 0b2ce2a0e72f590dd22ea5100496830c3627a9ac
sha256: 533f4eedf5284b8177c1c009c0113d32357a8353bf3e13097f3a0a88a2cce85f
sha512: 625dd49a78de0ac1cf88e19c29b0ce857f852e8203d5ecfe7d7005258997e74cf688cfc18f38705f926e6d0c03cdd01712ba5865e21ea9244ee71e4880e4c1ab
ssdeep: 12288:OBfPUJFneSNvle9jtj0M0m5xlSkJ+bEnJU:SeF1NitjvnxlSkJNn2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002-2003 Ada99.com
InternalName: book.exe
FileVersion: 1.4.0.0
CompanyName: Ada99.com
LegalTrademarks: $$
Comments: Create Professional eBooks
ProductName: eBook Workshop
ProductVersion: 1.4.0.0
FileDescription: eBook Workshop
OriginalFilename: book.exe
Translation: 0x0409 0x04e4

Trojan.Agent.EZKD also known as:

BkavW32.AIDetectVM.malware5
MicroWorld-eScanTrojan.Agent.EZKD
McAfeeArtemis!63F97FC0E953
CylanceUnsafe
VIPREAdaEbook (v) (not malicious)
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.EZKD
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Agent.EZKD
CyrenW32/Worm.QPOB-8824
ClamAVWin.Trojan.Agent-35756
SUPERAntiSpywareAdware.AdaEbook/Variant
Ad-AwareTrojan.Agent.EZKD
EmsisoftTrojan.Agent.EZKD (B)
ComodoMalware@#3w2i48fa20r8
F-SecurePotentialRisk.PUA/Agent.AF
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
FireEyeGeneric.mg.63f97fc0e953ed97
SophosAdaEbook (PUA)
IkarusTrojan.Inject
WebrootAdware.Adaebook.Gen
AviraPUA/Agent.AF
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftMalware.Win32.Gen.sm!s1
MicrosoftProgram:Win32/Wacapew.C!ml
GDataTrojan.Agent.EZKD
CynetMalicious (score: 100)
MalwarebytesAdware.ChinAd
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.2665045.susgen
FortinetW32/DrpWm.B9A4!tr
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Agent.EZKD?

Trojan.Agent.EZKD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment