Trojan

About “Trojan.Agent.VSH” infection

Malware Removal

The Trojan.Agent.VSH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.VSH virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Detects Bochs through the presence of a registry key

How to determine Trojan.Agent.VSH?


File Info:

name: 63EAE056F8B59540858B.mlw
path: /opt/CAPEv2/storage/binaries/f220ae80c842fe14e273aacff0e7918d55eabeee832871c48ddcfd7314bc0dad
crc32: E9B39374
md5: 63eae056f8b59540858bb2153e2e7c68
sha1: 17b5e3d1e5154ede09e62ccf4bb5f1861d57e845
sha256: f220ae80c842fe14e273aacff0e7918d55eabeee832871c48ddcfd7314bc0dad
sha512: 9dad6efbb6d1f54f11ebda194fc52b82684a831aa714a604b7aa6034e05d356553d0b604a6d3c6709c8e1ffbdd94748622ce467de0b788d66e6329968e0cad30
ssdeep: 12288:2hEGlbRvADcfKGYaRK4vkyhMtOQccm3AMWZtXsp8se8caCM7CsFbNBwgHv/XluH6:2hE6LetV2COpHluEnGgc2xVOw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2859DA6D2D8C249C541707C5E26B80E63F977FA91C6F482DE378A073D15BE8D82D0E6
sha3_384: 72534583014e8997ccdd4fb4c51873a08506cd707b97939dc745e275196604a4c920e9c4b4db5e313f1f15c0e75c3f91
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-03-23 08:18:21

Version Info:

FileDescription: Lights Standalone
Translation: 0x0000 0x04b0

Trojan.Agent.VSH also known as:

LionicTrojan.Win32.Heye.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen1.29435
MicroWorld-eScanIL:Trojan.MSILZilla.7441
FireEyeGeneric.mg.63eae056f8b59540
McAfeeArtemis!63EAE056F8B5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 00587d311 )
K7AntiVirusTrojan ( 00587d311 )
BitDefenderThetaGen:NN.ZemsilF.34182.Vn1@a8yZ9rd
SymantecW32.Golroted
ESET-NOD32a variant of MSIL/Injector.IRY
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.7441
NANO-AntivirusTrojan.Win32.Heye.dptrpt
AvastMSIL:GenMalicious-ESW [Trj]
Ad-AwareIL:Trojan.MSILZilla.7441
EmsisoftIL:Trojan.MSILZilla.7441 (B)
F-SecureHeuristic.HEUR/AGEN.1124747
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/Generic-L
IkarusTrojan.MSIL.Injector
GDataIL:Trojan.MSILZilla.7441
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1124747
Antiy-AVLTrojan[PSW]/Win32.Heye
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:MSIL/Obfuscator.AX
AhnLab-V3Trojan/Win32.ZBot.R139159
ALYacIL:Trojan.MSILZilla.7441
MAXmalware (ai score=80)
MalwarebytesTrojan.Agent.VSH
APEXMalicious
TencentWin32.Trojan-qqpass.Qqrob.Wqdm
YandexTrojan.PWS.Heye!FC7orZhdhCc
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Injector.IYP!tr
AVGMSIL:GenMalicious-ESW [Trj]
Cybereasonmalicious.6f8b59
PandaTrj/CI.A

How to remove Trojan.Agent.VSH?

Trojan.Agent.VSH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment