Trojan

Trojan.Agent.EZVD (file analysis)

Malware Removal

The Trojan.Agent.EZVD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EZVD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Trojan.Agent.EZVD?


File Info:

crc32: 63513D8F
md5: b6acf99584892096a0fc0a5063d722c0
name: B6ACF99584892096A0FC0A5063D722C0.mlw
sha1: b5446ab214cb5a08d572c28cc64d920966d8ee03
sha256: a8fa10846caf45356bd2e88eb46b4452ae07c84a7b106168f5eab2165ef01e23
sha512: 255ed6a470eb13c499a16127fc3b50a8b51120b12bb3deddd997d5e34aa979c4625b61b646cea04b1b4a7249099b45371752fe4fe504da7548107320959679fc
ssdeep: 6144:hTfmt7eZAPOyKmLrLqGvHr0nNK11G9DMQyaViFwRur:hbi7/xZrkNK11G9AQyOi6c
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.EZVD also known as:

BkavW32.malware.sig1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EZVD
FireEyeGeneric.mg.b6acf99584892096
ALYacTrojan.Agent.EZVD
CylanceUnsafe
SangforMalware
BitDefenderTrojan.Agent.EZVD
K7GWRiskware ( 0049f6ae1 )
K7AntiVirusRiskware ( 0049f6ae1 )
CyrenW32/Agent.CCJ.gen!Eldorado
SymantecTrojan.Maltrec.TS
ESET-NOD32a variant of Win32/GenCBL.NT
APEXMalicious
RisingTrojan.GenCBL!8.12138 (TFE:4:CKVnoSwwvO)
Ad-AwareTrojan.Agent.EZVD
SophosML/PE-A + Mal/EncPk-APW
F-SecureHeuristic.HEUR/AGEN.1134669
DrWebBackDoor.Qbot.554
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftMalCert.A (A)
AviraHEUR/AGEN.1134669
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Agent.EZVD
GDataTrojan.Agent.EZVD
CynetMalicious (score: 100)
McAfeeW32/PinkSbot-HE!B6ACF9958489
MAXmalware (ai score=87)
VBA32Malware-Cryptor.General.3
MalwarebytesTrojan.Cutwail
FortinetW32/Qbot.CU!tr
Qihoo-360Generic/HEUR/QVM39.1.B28C.Malware.Gen

How to remove Trojan.Agent.EZVD?

Trojan.Agent.EZVD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment