Malware

Downloader.Win32.Agent.mlzt removal guide

Malware Removal

The Downloader.Win32.Agent.mlzt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mlzt virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Steals private information from local Internet browsers

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.mlzt?


File Info:

crc32: 42064FCC
md5: 166404ca54942dec50c03945324d5637
name: 166404CA54942DEC50C03945324D5637.mlw
sha1: 3be080714f7fab92001b055d915805aa95fad66c
sha256: 375da28284aab4fd20303c895caf56373f12faa4932e93f0fe39062088e92246
sha512: 708f1115313ba24ac269e3f76adbdbe4e2a75c30b767d6be023a070085eab7c0e6195bb28d9c105abcbb97baabbb90472a57b4c6bed7c7d68916698b2b75e626
ssdeep: 24576:HSGQZ9TvUGHmSAEPyuXNBWcD9vPzU3sxvbvF9O+SjmGTZNsmiid:HSfDGSAEpvs4jiFmQs6d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.1117
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mlzt also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Zusy.189946
FireEyeGen:Variant.Adware.Zusy.189946
ALYacGen:Variant.Adware.Zusy.189946
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 00510c5c1 )
BitDefenderGen:Variant.Adware.Zusy.189946
K7GWAdware ( 00510c5c1 )
CyrenW32/Adware.CSTJ-3574
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:Downloader.Win32.Agent.mlzt
AlibabaDownloader:Win32/Qjwmonkey.4883b702
TencentMalware.Win32.Gencirc.11b17ffa
Ad-AwareGen:Variant.Adware.Zusy.189946
EmsisoftApplication.Downloader (A)
ComodoApplicUnwnt@#das9bk5x5yya
F-SecureAdware.ADWARE/Qjwmonkey.Gen
DrWebAdware.Qjwmonkey.168
TrendMicroPUA.Win32.QJWMonkey.IH
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA DL (PUA)
WebrootW32.Trojan.Gen
AviraADWARE/Qjwmonkey.Gen
eGambitTrojan.Generic
MAXmalware (ai score=64)
MicrosoftPUA:Win32/Qjwmonkey
GridinsoftTrojan.Qjwmonkey.dd!c
ArcabitTrojan.Adware.Zusy.D2E5FA
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mlzt
GDataGen:Variant.Adware.Zusy.189946
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Qjwmonkey.R351850
McAfeeArtemis!166404CA5494
VBA32BScope.TrojanDropper.Dapato
MalwarebytesAdware.ChinAd
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallPUA.Win32.QJWMonkey.IH
RisingAdware.Downloader!1.BDCA (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Downloader.Win32.Agent.mlzt?

Downloader.Win32.Agent.mlzt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment