Malware

AdWare.Win32.Agent.vho removal instruction

Malware Removal

The AdWare.Win32.Agent.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Agent.vho virus can do?

  • Presents an Authenticode digital signature
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
api.ip138.com
a.tomx.xyz
dwoncdn.xiald.com
down.xiald.com
dwoncdn2.xiald.com
www.9973.com
xzqtj.xiald.com

How to determine AdWare.Win32.Agent.vho?


File Info:

crc32: 7F7D31C3
md5: 57a071b5825024c9ca5da5cafdbb3acf
name: __________________________________131_38913.exe
sha1: 1b8684d0f926a2d821c32faeb0e4a2f0c3f63376
sha256: 40cffa8ccb85ce9208113cf08cdbaa0a00a98203d711fc5c622a03eb3dc6d9ee
sha512: f7ba56034870112456762d8f2b738440036aa1434beaa5c926c1e0885d24d5ae768f0bd41c92f390823db6b22845baa6f16bf31ea84aaad29bad213261355e11
ssdeep: 49152:TzLVynqoU3Zcahlaxi+luQpUyHYhIsuetadb7d49qZHWnPI45Lr:pMqola0i+luHjueta9ZKqsnP9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x9ad8x901fx4e0bx8f7dx5668
FileVersion: 1.5.6.191015
CompanyName: x9ad8x901fx4e0bx8f7dx5668
ProductName: x9ad8x901fx4e0bx8f7dx5668
ProductVersion: 1,5,6,191015
FileDescription: x9ad8x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

AdWare.Win32.Agent.vho also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.32832983
FireEyeTrojan.GenericKD.32832983
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.GenericKD.32832983
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004d97001 )
BitDefenderTrojan.GenericKD.32832983
K7GWAdware ( 004d97001 )
CrowdStrikewin/malicious_confidence_60% (D)
AvastWin32:AdwareX-gen [Adw]
GDataTrojan.GenericKD.32832983
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.vho
AlibabaAdWare:Win32/Softcnapp.90720dc2
ViRobotAdware.Strictor.2529704
TencentWin32.Adware.Agent.Sxem
Ad-AwareTrojan.GenericKD.32832983
EmsisoftTrojan.GenericKD.32832983 (B)
ComodoMalware@#2faoae76y79dy
DrWebAdware.Softcnapp.119
ZillyaAdware.Agent.Win32.146417
Invinceaheuristic
McAfee-GW-EditionGenericRXJC-ZY!57A071B58250
SentinelOneDFI – Suspicious PE
SophosSoftcnapp (PUA)
APEXMalicious
CyrenW32/Trojan.BKZZ-5323
JiangminAdware.Agent.akso
WebrootW32.Adware.Gen
Antiy-AVLGrayWare[AdWare]/Win32.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F4FDD7
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Agent.vho
MicrosoftPUA:Win32/CoinMiner
McAfeeGenericRXJC-ZY!57A071B58250
MAXmalware (ai score=99)
VBA32BScope.Adware.Puwaders
MalwarebytesPUP.Optional.Softcnapp
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
RisingAdware.Downloader!1.BBEC (CLOUD)
FortinetAdware/Agent
AVGWin32:AdwareX-gen [Adw]
MaxSecureTrojan.Malware.73379846.susgen

How to remove AdWare.Win32.Agent.vho?

AdWare.Win32.Agent.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment