Malware

What is “Downloader.Win32.Agent.vho”?

Malware Removal

The Downloader.Win32.Agent.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.vho virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Downloader.Win32.Agent.vho?


File Info:

crc32: 6CD41BCC
md5: c66e73b6ce6ca5ad11472a6832f5ec54
name: omronplcE7BC96E7A88BE8BDAFE4BBB6cx-onev4.31E4B8ADE69687E5858DE8B4B9E78988E99984E5BA8FE58897E58FB7E5A
sha1: 8ab6c4f0172f4d190ff6e347689dc15232a34264
sha256: df8288a11113795d5b2c398544b3b794cab7d8142f53dd6e0ceeb49a1252edf7
sha512: 033402276af6a62f995ed22c07b72ecee9d1c3a428e94a56cc75d0a34998e4905ae0fa1bbf7550fbfcf561ca8bb63c4ceb252ad2a2f611b0c6e9d0520505180b
ssdeep: 24576:cYZBz6rCOS1JuaaHjfm8vOaD+pzqM4HH0X6rIsffr/yWdmNUw5Ml:cYnOsJGnCpuz0XGffr7dmel
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.214
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.214
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.vho also known as:

DrWebAdware.Qjwmonkey.168
MicroWorld-eScanGen:Variant.Ulise.101455
FireEyeGeneric.mg.c66e73b6ce6ca5ad
CAT-QuickHealTrojan.IGENERIC
McAfeeQJWMonkey
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 005105151 )
BitDefenderGen:Variant.Ulise.101455
K7GWAdware ( 005105151 )
Cybereasonmalicious.6ce6ca
TrendMicroTROJ_GEN.R020C0PBS20
F-ProtW32/Qjwmonkey.G.gen!Eldorado
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
APEXMalicious
AvastWin32:PUPX-gen [PUP]
GDataGen:Variant.Ulise.101455
Kasperskynot-a-virus:HEUR:Downloader.Win32.Agent.vho
AlibabaAdWare:Win32/Qjwmonkey.05c79d02
NANO-AntivirusTrojan.Win32.Qjwmonkey.hccbwn
RisingAdware.Downloader!1.BDCA (CLOUD)
Ad-AwareGen:Variant.Ulise.101455
SophosQjMonkey (PUA)
ComodoApplication.Win32.Qjwmonkey.HU@8hjovh
F-SecureHeuristic.HEUR/AGEN.1042852
ZillyaAdware.Qjwmonkey.Win32.616
Invinceaheuristic
McAfee-GW-EditionQJWMonkey
EmsisoftGen:Variant.Ulise.101455 (B)
IkarusPUA.Qjwmonkey
CyrenW32/Qjwmonkey.G.gen!Eldorado
JiangminDownloader.Agent.mlt
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1042852
Antiy-AVLGrayWare/Win32.Qjwmonkey
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D18C4F
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Agent.vho
MicrosoftPUA:Win32/Qjwmonkey
AhnLab-V3PUP/Win32.RL_Qjwmonkey.R287544
VBA32BScope.Adware.Qjwmonkey
ALYacGen:Variant.Ulise.101455
MAXmalware (ai score=81)
MalwarebytesAdware.ChinAd
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R020C0PBS20
YandexPUA.Qjwmonkey!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGFileRepMalware [PUP]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.121218.susgen

How to remove Downloader.Win32.Agent.vho?

Downloader.Win32.Agent.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment