Trojan

About “Trojan.Ezhk” infection

Malware Removal

The Trojan.Ezhk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ezhk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Ezhk?


File Info:

crc32: 208D9E28
md5: 6a637e037c9dd6b7ba60cd7e072dbb1f
name: 6A637E037C9DD6B7BA60CD7E072DBB1F.mlw
sha1: 1b9c9bcc8c71464679fcb8ab52e3276a3dc11490
sha256: fd4ea47288b9cc7d4c7d2f29720c1f7da5942fd3683140b28b5dbf5ad87a5106
sha512: bb62db685414fd837e96143b16d4f7e874fbcd0bdfe168224949d65ee4c4e07373a3ec2d97ae810fb1acbd76968dada2ba37459f39d2a9ba7badf3bbecc03ab7
ssdeep: 3072:difRZP/MoiW9ce5eix8l2UmeYIQqpAFsndgdNiEhILSx3r:IfvMoF9KixiYbqpiYgNiEhI2r
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ezhk also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45255384
FireEyeGeneric.mg.6a637e037c9dd6b7
CAT-QuickHealTrojan.Ezhk
McAfeeEmotet-FRR!6A637E037C9D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.45255384
K7GWTrojan ( 00575b801 )
K7AntiVirusTrojan ( 00575b801 )
CyrenW32/Emotet.AZU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
AlibabaTrojan:Win32/EmotetCrypt.be183d61
AegisLabTrojan.Win32.Emotet.L!c
RisingTrojan.Kryptik!1.D077 (CLASSIC)
Ad-AwareTrojan.GenericKD.45255384
EmsisoftTrojan.GenericKD.45255384 (B)
F-SecureTrojan.TR/AD.Emotet.gbg
DrWebTrojan.Emotet.1070
TrendMicroTROJ_GEN.R002C0DA321
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
SophosMal/Generic-R + Troj/Emotet-CVD
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Emotet.vo
AviraTR/AD.Emotet.gbg
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
MicrosoftTrojan:Win32/EmotetCrypt.SS!MTB
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.Generic.D2B28AD8
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.pef
GDataTrojan.GenericKD.45255384
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R361809
ALYacTrojan.Agent.Emotet
MAXmalware (ai score=84)
VBA32Trojan.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/GdSda.A
ESET-NOD32Win32/Emotet.CN
TrendMicro-HouseCallTROJ_GEN.R002C0DA321
TencentMalware.Win32.Gencirc.10ce3066
IkarusTrojan-Banker.Emotet
FortinetW32/Kryptik.HILQ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.f34

How to remove Trojan.Ezhk?

Trojan.Ezhk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment