Trojan

Trojan.ProcessHijack.emNfaGztTVci (file analysis)

Malware Removal

The Trojan.ProcessHijack.emNfaGztTVci is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ProcessHijack.emNfaGztTVci virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Trojan.ProcessHijack.emNfaGztTVci?


File Info:

crc32: ED72E7F4
md5: 907e50d6c8f71a96ac0bc7b502f680b8
name: 907E50D6C8F71A96AC0BC7B502F680B8.mlw
sha1: 836e5c75c739d1b990412825d486737959891569
sha256: 29f3ebc0b94ca3e153dd880b9042bbc1c35ee84931464687f0676720fdd60550
sha512: dfb9e82375e1268c7bbbb8db5e55683163aa0f28e1be5b400ef06b6852b5117a2738e36b47effd13973c4f6abef5f4306d3548181640dd0a890891ac8dd08b05
ssdeep: 1536:tyq7zh1HpIfQQFfBeFcRO67Ssgh0b2XQoqSG5GodjhyBNHN:v7zhJpIfQQvX3SRh0KAoqhYejcHHN
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: SnapAst
FileVersion: 1.00
CompanyName: x413x435x43ex434x430x442x430 x413x430x434x436x435x442 Toolz
ProductName: SnapAst
ProductVersion: 1.00
OriginalFilename: SnapAst.exe

Trojan.ProcessHijack.emNfaGztTVci also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.6809
CynetMalicious (score: 90)
ALYacGen:Trojan.ProcessHijack.emNfaGztTVci
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.62208
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:Win32/Blocker.05000e80
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.6c8f71
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.WUI
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.kktt
BitDefenderGen:Trojan.ProcessHijack.emNfaGztTVci
NANO-AntivirusTrojan.Win32.Gimemo.zkzbe
MicroWorld-eScanGen:Trojan.ProcessHijack.emNfaGztTVci
TencentWin32.Trojan.Gimemo.Hrfa
Ad-AwareGen:Trojan.ProcessHijack.emNfaGztTVci
SophosMal/Generic-S
ComodoMalware@#2777gbptyz6h8
BitDefenderThetaGen:NN.ZevbaCO.34608.emNfaGztTVci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.kc
FireEyeGeneric.mg.907e50d6c8f71a96
EmsisoftGen:Trojan.ProcessHijack.emNfaGztTVci (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Heur
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Dynamer!dtc
ArcabitTrojan.ProcessHijack.emNfaGztTVci
AegisLabTrojan.Win32.Gimemo.j!c
GDataGen:Trojan.ProcessHijack.emNfaGztTVci
AhnLab-V3Trojan/Win32.Gimemo.C2256697
McAfeeArtemis!907E50D6C8F7
MAXmalware (ai score=86)
VBA32Hoax.Gimemo
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
RisingRansom.Gimemo!8.306 (CLOUD)
IkarusTrojan-Ransom.Gimemo
FortinetW32/Injector.YUP!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwsBoQwA

How to remove Trojan.ProcessHijack.emNfaGztTVci?

Trojan.ProcessHijack.emNfaGztTVci removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment