Trojan

Trojan.Crypt.EJ (B) removal guide

Malware Removal

The Trojan.Crypt.EJ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.EJ (B) virus can do?

  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

dns-blabla.com
dns-blabla.net

How to determine Trojan.Crypt.EJ (B)?


File Info:

crc32: 71D015FE
md5: 192b519db8b0bae6e83d50cea94218ec
name: 192B519DB8B0BAE6E83D50CEA94218EC.mlw
sha1: 55117df509f074517c77b9a3e4ca87b9a4a2e0a0
sha256: d3d9b79d51e6c730b0e417af51c6798dc21f175abe59c81153e166b04da5e9a0
sha512: 29011d2e4c9592d073a43143724485995c5e149fb29366de0589e5c4dc133aaae58a0f13ae9b14085e53f34af0251108da7272d6d8ea6a2adbfb77740e0ae44d
ssdeep: 6144:QMoK0zaHdLIKbSNmvbSO0bS2AmbSYCqbSxbS3bS1TaRDi8bdbSankP+6bwnkP+6v:uK0MhHT2LPemnDLxQ+m+AeDR+Au
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Crypt.EJ (B) also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.EJ
FireEyeGeneric.mg.192b519db8b0bae6
CAT-QuickHealWorm.Socks.13494
ALYacTrojan.Crypt.EJ
CylanceUnsafe
VIPREP2P-Worm.Win32.Socks.g (fs)
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 005662bd1 )
BitDefenderTrojan.Crypt.EJ
K7GWEmailWorm ( 005662bd1 )
Cybereasonmalicious.db8b0b
BaiduWin32.Trojan-PSW.Agent.b
CyrenW32/Socks.A.gen!Eldorado
SymantecW32.Mandaph
TotalDefenseWin32/Korced!generic
APEXMalicious
ClamAVWin.Worm.Socks-8977521-0
KasperskyTrojan-Ransom.Win32.Blocker.itys
AlibabaWorm:Win32/Blocker.b8b3e784
NANO-AntivirusTrojan.Win32.Socks.lpxw
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareTrojan.Crypt.EJ
EmsisoftTrojan.Crypt.EJ (B)
ComodoMalware@#f9801soghd01
F-SecureTrojan.TR/Dldr.Agent.agl
DrWebTrojan.Siggen10.38737
ZillyaWorm.Socks.Win32.284
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
MaxSecureWorm.Socks
SophosMal/Generic-S
IkarusVirus.Worm.Win32.Socks.afv
JiangminWorm/Socks.ni
AviraTR/Dldr.Agent.agl
Antiy-AVLWorm/Win32.Socks
MicrosoftWorm:Win32/Autorun
ArcabitTrojan.Crypt.EJ
ZoneAlarmTrojan-Ransom.Win32.Blocker.itys
GDataTrojan.Crypt.EJ
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R2364
McAfeeGenericRXAA-AA!192B519DB8B0
MAXmalware (ai score=84)
VBA32SScope.Worm.Socks.afv
MalwarebytesGeneric.Worm.Autorun.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Socks.NAJ
TrendMicro-HouseCallWORM_SOCKS.BL
TencentMalware.Win32.Gencirc.10b07679
YandexTrojan.GenAsa!XFaKFzne070
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Socks.HF!worm
BitDefenderThetaAI:Packer.8D6A39611B
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Blocker.HwsBDGcA

How to remove Trojan.Crypt.EJ (B)?

Trojan.Crypt.EJ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment