Malware

Exploit.Win32.Agent.ivp (file analysis)

Malware Removal

The Exploit.Win32.Agent.ivp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Agent.ivp virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Exploit.Win32.Agent.ivp?


File Info:

name: E9B52E3D0901BBBBA613.mlw
path: /opt/CAPEv2/storage/binaries/729c0d1b14d5130031113ff961f7df62c1c26e4fb668bae0102db64b0948d92c
crc32: 70947890
md5: e9b52e3d0901bbbba61392c66f4daf13
sha1: d075e7edfeb009394073b2cdf1dd98dc5a829937
sha256: 729c0d1b14d5130031113ff961f7df62c1c26e4fb668bae0102db64b0948d92c
sha512: 3107b413dd9227e04f4a5f1293b3ae4055977b3fdc448f50b5bbb72f2be3d4f4d3510b16907bee6850698b78844aa148462855b1e2da515ec4c4f462e7542718
ssdeep: 3072:gGihmVFmEhmc1vacsWt//Ckqoyb1vVit2VImmDBJ9xp/TrUg:gpmVFmnc1BsWtikqoybHiYsT9DUg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19E340889FB53C1B1F62700F42059EFFD55207012D87FA9AADAF6BC12A971E3A1011F5A
sha3_384: 783c21c9acce0bf3bac7484f2a5c1ec8bed51c2a0bf18a880fb2865450a3ca026328c8117aea7ce6a7120f0ce6ffb5a9
ep_bytes: c7055c90430000000000e9b1fcffff90
timestamp: 2022-09-06 14:53:31

Version Info:

0: [No Data]

Exploit.Win32.Agent.ivp also known as:

MicroWorld-eScanTrojan.GenericKD.61813651
FireEyeGeneric.mg.e9b52e3d0901bbbb
ALYacTrojan.GenericKD.61813651
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/GenKryptik.f0adb0b1
Cybereasonmalicious.dfeb00
CyrenW32/Dropper.6!Generic
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Spy.Agent.DFY
APEXMalicious
Paloaltogeneric.ml
KasperskyExploit.Win32.Agent.ivp
BitDefenderTrojan.GenericKD.61813651
AvastWin32:Trojan-gen
TencentWin32.Exploit.Agent.Kqil
Ad-AwareTrojan.GenericKD.61813651
ComodoMalware@#qvktvalcllce
DrWebTrojan.PWS.StealerNET.125
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.61813651 (B)
IkarusTrojan.Agent
GDataTrojan.GenericKD.61813651
GoogleDetected
AviraTR/AD.Nekark.lvmwp
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.5123
ArcabitTrojan.Generic.D3AF3393
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5233516
Acronissuspicious
McAfeeArtemis!E9B52E3D0901
VBA32BScope.TrojanDownloader.Alien
MalwarebytesMalware.AI.4168729592
TrendMicro-HouseCallTROJ_GEN.R002H0DI622
RisingBackdoor.Agent!8.C5D (TFE:5:b6nsUDfCX5V)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/DotNetPacker.A!tr
BitDefenderThetaGen:NN.ZexaF.34646.oCW@aa9JbU
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Exploit.Win32.Agent.ivp?

Exploit.Win32.Agent.ivp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment