Trojan

Trojan.Agent.FHGV removal guide

Malware Removal

The Trojan.Agent.FHGV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FHGV virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan.Agent.FHGV?


File Info:

crc32: 7EC22843
md5: 1cd8451d43e2ae8e4ab3d5fea966d261
name: 1CD8451D43E2AE8E4AB3D5FEA966D261.mlw
sha1: 42e62ada2d58406160cad95c3701327b4e26421a
sha256: bf7321ca589fbd52a5069143c715f4366923800b53820e4a8e7f9301bc8f0b8e
sha512: b7cdc111cab45ed4411dc1f831531ce0107258ba906fc8e540e604a4ee75922e2645f2b2f5d842e91dd274ae38014a372507ae4e92904faae404beb323892f23
ssdeep: 12288:GqkpqRJ6oFDnJVs+3i83i4Bx+a/wiye17x:1DJJyB4ewwxeh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: ordinaryfits.exe
FileVersion: 136.0.50.391
CompanyName: Maras Group
ProductName: SQL Database
ProductVersion: 136.0.50.391
FileDescription: .NET Config File Wrapper
OriginalFilename: ordinaryfits.exe
Translation: 0x0000 0x04b0

Trojan.Agent.FHGV also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.16003
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.a2d584
ESET-NOD32a variant of Win32/GenKryptik.FFFT
APEXMalicious
AvastWin32:BankerX-gen [Trj]
BitDefenderTrojan.Agent.FHGV
MicroWorld-eScanTrojan.Agent.FHGV
Ad-AwareTrojan.Agent.FHGV
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34688.Du0@aakGLBhc
FireEyeGeneric.mg.1cd8451d43e2ae8e
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Script/Phonzy.B!ml
GDataTrojan.Agent.FHGV
MAXmalware (ai score=86)
RisingTrojan.GenKryptik!8.AA55 (RDMK:cmRtazqSEZHNXSqniFW5JwfVDYpN)
AVGWin32:BankerX-gen [Trj]

How to remove Trojan.Agent.FHGV?

Trojan.Agent.FHGV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment