Trojan

Trojan.Win32.DLLhijack.ei (file analysis)

Malware Removal

The Trojan.Win32.DLLhijack.ei is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.DLLhijack.ei virus can do?

  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Creates a hidden or system file
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

kumar807.blogspot.com
kumar807.wordpress.com
kumar807.livejournal.com

How to determine Trojan.Win32.DLLhijack.ei?


File Info:

crc32: 32758E6F
md5: 6b8ea12d811acf88f94b734bf5cfbfb3
name: 0eb038e7e5edd6ac1b4eee8dd1c51b6d94da24d02ba705e7e7f10b41edf701c2
sha1: ae93cb98812fa8de21ab8ca21941b01d770272e9
sha256: 0eb038e7e5edd6ac1b4eee8dd1c51b6d94da24d02ba705e7e7f10b41edf701c2
sha512: 43fa6573b31b689edbe06495c40656dd330859ce00e0a9b620c428801dfc1d89c4ac38b5b6fb0b16df94b8bb2e3a92b118d99ab610948cbf5bb4c30f9964dd29
ssdeep: 768:j5QGuIOFwKTMAj3cdXhwlbapQ8OsHBiR+hYHAGQ:VsIOFwKT/BlbapQH05WQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.DLLhijack.ei also known as:

DrWebTrojan.Wmighost.9
MicroWorld-eScanGen:Variant.Symmi.59398
FireEyeGeneric.mg.6b8ea12d811acf88
CAT-QuickHealTrojan.Dynamer.A4
McAfeeGenericR-FMW!6B8EA12D811A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004a0b431 )
BitDefenderGen:Variant.Symmi.59398
K7GWTrojan ( 004a0b431 )
Cybereasonmalicious.d811ac
TrendMicroTROJ_SYNDICASEC.A
BitDefenderThetaGen:NN.ZexaF.33558.dqW@aiU05dgb
F-ProtW32/WMIGhost.A.gen!Eldorado
SymantecTrojan.Syndicasec
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Syndicasec-6609573-0
GDataGen:Variant.Symmi.59398
KasperskyTrojan.Win32.DLLhijack.ei
AlibabaTrojan:Win32/Syndicasec.a06f9424
NANO-AntivirusTrojan.Win32.Dwn.deefhc
AegisLabTrojan.Win32.DLLhijack.4!c
RisingBackdoor.Weemurl!8.31ED (TFE:5:ZBx5yTm0IrM)
Ad-AwareGen:Variant.Symmi.59398
SophosTroj/Thetatic-O
ComodoMalware@#25r11xozm23yy
F-SecureHeuristic.HEUR/AGEN.1018775
ZillyaTrojan.Agentb.Win32.5284
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.qt
EmsisoftGen:Variant.Symmi.59398 (B)
IkarusTrojan.Win32.Syndicasec
CyrenW32/WMIGhost.A.gen!Eldorado
JiangminTrojan.Agentb.qf
WebrootW32.Gen.BT
AviraHEUR/AGEN.1018775
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Symmi.DE806
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmTrojan.Win32.DLLhijack.ei
MicrosoftTrojan:Win32/Syndicasec
AhnLab-V3Trojan/Win32.Agentb.R139589
ALYacGen:Variant.Symmi.59398
MAXmalware (ai score=100)
VBA32Trojan.Agentb
PandaTrj/CI.A
ESET-NOD32Win32/Syndicasec.F
TrendMicro-HouseCallTROJ_SYNDICASEC.A
TencentMalware.Win32.Gencirc.10b3dff9
YandexTrojan.Agentb!+O/38dHvHR4
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agentb.BEVF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.6f3

How to remove Trojan.Win32.DLLhijack.ei?

Trojan.Win32.DLLhijack.ei removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment