Malware

Server-FTP.Win32.Agent.h (file analysis)

Malware Removal

The Server-FTP.Win32.Agent.h is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Server-FTP.Win32.Agent.h virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Server-FTP.Win32.Agent.h?


File Info:

name: CA3A0A16ABDF1D86085D.mlw
path: /opt/CAPEv2/storage/binaries/35555d33b8f9ac6a8ff2fc8a40178ba20ffe08c97ab3e3584938b9019be827f5
crc32: A8954DA8
md5: ca3a0a16abdf1d86085dd0f47b3630c7
sha1: c3f7f800aacf1ad34667ec679edea777f5e3c104
sha256: 35555d33b8f9ac6a8ff2fc8a40178ba20ffe08c97ab3e3584938b9019be827f5
sha512: 52807ddf38ff1056f4261a91e12b6b2c663c7dd568cdf82ca606267dc8534a648a2ffa686788a99eb9d7b963eae061bda820c94632f72a232a216c3c4dd97d46
ssdeep: 98304:gS/2LbSTBGGJ78ZrEiN/Gf4MOxUO7dfdnH:p+bS1G28hEUWhgpH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A72633C67631197CC9F8CB73A5BA6DBF8B501C2D358D07497850FA2D2A3E2AB4534CA4
sha3_384: af28e44bd5c5b6850a14d8cf6f2e875436c0e28f7013b3ed6e1d56966a922fbf40a3f63f4b5a93224a474b5a70aff1d3
ep_bytes: 60be008048008dbe0090f7ff57eb0b90
timestamp: 2010-04-16 07:47:33

Version Info:

FileVersion: 6.1.M.0
Comments: 网络克隆自动版 6.1M_x86
FileDescription: 网络克隆自动版 6.1M_x86
LegalCopyright: CYG 工作室
Translation: 0x0804 0x04b0

Server-FTP.Win32.Agent.h also known as:

LionicRiskware.Win32.Agent.1!c
CAT-QuickHealTrojan.Mauvaise.S2595919
SkyhighBehavesLike.Win32.BadFile.rc
Cylanceunsafe
ZillyaTrojan.TFTPD32.Win32.3
SangforPUP.Win32.Bitrepeyp.A
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
VirITTrojan.Win32.Generic.CAHB
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TFTPD32.B potentially unsafe
CynetMalicious (score: 100)
Kasperskynot-a-virus:Server-FTP.Win32.Agent.h
NANO-AntivirusRiskware.Win32.Ftpd.kdkrzy
AvastFileRepMalware [Misc]
TencentMalware.Win32.Gencirc.10beac8f
SophosGeneric Reputation PUA (PUA)
DrWebProgram.Ftpd.1
TrendMicroPUA.Win32.TFTPServer.A
IkarusPUA.TFTPD32
WebrootW32.Sfh.Jv
Antiy-AVLRiskWare/Win32.TFTPD32.b
XcitiumSuspicious@#pxwm18cxua7m
ZoneAlarmnot-a-virus:Server-FTP.Win32.Agent.h
MicrosoftTrojan:Win32/Occamy.C35
McAfeeArtemis!CA3A0A16ABDF
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallPUA.Win32.TFTPServer.A
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Pioneer.H
FortinetRiskware/TFTPD32
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove Server-FTP.Win32.Agent.h?

Server-FTP.Win32.Agent.h removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment