Trojan

Trojan.Win32.Agent.idyp (file analysis)

Malware Removal

The Trojan.Win32.Agent.idyp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.idyp virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Agent.idyp?


File Info:

name: 33469FDC958DBE0ED90E.mlw
path: /opt/CAPEv2/storage/binaries/2949ec690f74362e249cafff2793802d4657a127f605579dfaf0a8eb94cde2fc
crc32: BA4C8A7C
md5: 33469fdc958dbe0ed90ea3f6ca5d9bf6
sha1: e1f5ff69eb8d508bbf908251b0cf078a7c70df0d
sha256: 2949ec690f74362e249cafff2793802d4657a127f605579dfaf0a8eb94cde2fc
sha512: 0cc64d0dcade6991a7a7c1b0e7f7aaee5e086525aede2a504f975a06f4cc80351f1bf49e50ee45fb790f918e2b09f0e5d724d8c54ee37d74d4055e6455df433d
ssdeep: 3072:dt5UTlAVVF3FFOEPbpPcJHnKvt0ljiE7I57tmwulHlOTpnUZb:DqAVVF3F3BMHnKKW5tlu+Tp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140747D2332D0C8F7C69711308EF2ABBBA2B9FB504F238993A3945B1D5E315928729755
sha3_384: 6e104ddbad8326836a18313576b06229cbef785f8b0df7b753f3aadc3c7a8973ebf5fae0b9dfe1802fa5dcfcd71d5321
ep_bytes: 558bec6aff68587542006858e0400064
timestamp: 2014-11-13 06:30:32

Version Info:

Comments:
CompanyName: Micsoft
FileDescription: Mic应用程序
FileVersion: 3, 8, 2, 0
InternalName: sever
LegalCopyright: 版权所有 (C) 2015
LegalTrademarks:
OriginalFilename: BTsever.EXE
PrivateBuild:
ProductName: BTsever 应用程序
ProductVersion: 9, 5, 2, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.Win32.Agent.idyp also known as:

LionicTrojan.Win32.Agent.4!c
McAfeeArtemis!33469FDC958D
CylanceUnsafe
SangforTrojan.Win32.Agent.8
AlibabaTrojan:Win32/Generic.aee5d609
Cybereasonmalicious.9eb8d5
APEXMalicious
KasperskyTrojan.Win32.Agent.idyp
NANO-AntivirusTrojan.Win32.Agent.dprloy
AvastWin32:Malware-gen
TencentWin32.Trojan.Agent.Lhna
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.33469fdc958dbe0e
IkarusTrojan-Dropper.Agent
AviraTR/Agent.341216
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32Trojan.Agent
MAXmalware (ai score=98)
RisingTrojan.Generic@ML.85 (RDML:HfMNZfrjzRdnlSaYN/u26Q)
YandexTrojan.Agent!fq0U1GVa5dk
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaE.34294.uq3@am4qhUgb
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Agent.idyp?

Trojan.Win32.Agent.idyp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment