Trojan

Trojan.Win32.Agent.idhi (file analysis)

Malware Removal

The Trojan.Win32.Agent.idhi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.idhi virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Agent.idhi?


File Info:

name: DEB2B7216F62EA2D6851.mlw
path: /opt/CAPEv2/storage/binaries/7924f738fd4d139b67b4a93617ba5f03ecd14f879c15caed0f931256ed98bb2e
crc32: AD6DDA19
md5: deb2b7216f62ea2d6851c291efa06b43
sha1: 57cc6587286524fe56bde62d6a93f52b8c130099
sha256: 7924f738fd4d139b67b4a93617ba5f03ecd14f879c15caed0f931256ed98bb2e
sha512: 2c96419b1052aaca715788761a1d7b827aa4149b4e19f52298b7fec9c7c557b56f85e42472c63ca0ab0c960defd360d1196852f71494bba476e404e58f739698
ssdeep: 768:8gNgU3AskqeBjuN3H8e1M3ufNGUgK5Mnctu4QtPZu:8mR30FjG38e1oul4K5M0uL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2535A62A9D28172C992417104B69302A767AC1607FE96177BECFD9BBF332D0D936307
sha3_384: d814e5132844495d49b5d32867223aa02a6b9cf19b588b00c281f1ea81b9faf8cddf98893bf97487e326db32abcd36b3
ep_bytes: c18560ffffffeb5abac14d8b8d0000e0
timestamp: 2013-11-25 21:39:07

Version Info:

0: [No Data]

Trojan.Win32.Agent.idhi also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.403837
FireEyeGeneric.mg.deb2b7216f62ea2d
McAfeeArtemis!DEB2B7216F62
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.36132.emX@aiKJh@c
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.idhi
BitDefenderGen:Variant.Zusy.403837
TencentMalware.Win32.Gencirc.10be8a28
EmsisoftGen:Variant.Zusy.403837 (B)
F-SecureTrojan.TR/Spy.Zbot.3566481
DrWebTrojan.DownLoad3.30762
VIPREGen:Variant.Zusy.403837
McAfee-GW-EditionGenericRXVS-KR!DEB2B7216F62
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.403837
AviraTR/Spy.Zbot.3566481
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Zusy.D6297D
ZoneAlarmTrojan.Win32.Agent.idhi
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Agent.C5402798
MalwarebytesWaski.Trojan.Downloader.DDS
ZonerTrojan.Win32.19563
TrendMicro-HouseCallTROJ_UPATRE.SMN7
RisingTrojan.Spy.Win32.Zbot.gal (CLASSIC)
IkarusTrojan.Retapu.D
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/UPATRE.SMN7!tr
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Agent.idhi?

Trojan.Win32.Agent.idhi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment