Trojan

About “Trojan.Win32.Agent.ilde” infection

Malware Removal

The Trojan.Win32.Agent.ilde is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.ilde virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan.Win32.Agent.ilde?


File Info:

name: EFB1DFF20100D6BFA5E5.mlw
path: /opt/CAPEv2/storage/binaries/94eb76cd2d6e8540b7a0e2661a6f0354fcc79951eec88b085331b531bb07fa28
crc32: E008B0A9
md5: efb1dff20100d6bfa5e50dd2b6749f59
sha1: 240f59176b8fce1867d9db7e36bb7be55b6121cf
sha256: 94eb76cd2d6e8540b7a0e2661a6f0354fcc79951eec88b085331b531bb07fa28
sha512: bc338ae754718c5f64967f979a93b42ec9d432cc7d566fdb0f094bb53d68196adcceadd47aa31e0293856bfc11fc873fa286c42d3d5460c3af6d70d3b9c95d89
ssdeep: 768:MApQr0ovdFJI34eGxusOy9Rp1pLeAxoeC48PqK12:MAaDJlMsh7pWezR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F703D752B2208B28C9B8A334040EBAF81E729D8FD649841FD617F874D9B95C3D33DB19
sha3_384: d354afe589fe48437d018ff4f992d55681c275648f615bd82452236189f058c7c6ec92843afe1e0edc916dda3fc860a7
ep_bytes: 558bec6aff6888204000685018400064
timestamp: 2006-07-02 14:19:05

Version Info:

0: [No Data]

Trojan.Win32.Agent.ilde also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Sdter.40
MicroWorld-eScanGen:Trojan.Heur.cuY@HPIO3zfb
FireEyeGeneric.mg.efb1dff20100d6bf
SkyhighBehavesLike.Win32.Generic.pm
McAfeeArtemis!EFB1DFF20100
Cylanceunsafe
ZillyaDropper.Agent.Win32.577512
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Generic.83c8457d
K7GWTrojan ( 005b3a2f1 )
K7AntiVirusTrojan ( 005b3a2f1 )
BitDefenderThetaAI:Packer.A099277F1C
VirITTrojan.Win32.Loan.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SOI
APEXMalicious
KasperskyTrojan.Win32.Agent.ilde
BitDefenderGen:Trojan.Heur.cuY@HPIO3zfb
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Loan.ha
EmsisoftGen:Trojan.Heur.cuY@HPIO3zfb (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPREGen:Trojan.Heur.cuY@HPIO3zfb
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDownloader.Loan.h
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Heuristic-XEN!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Loan
Kingsoftmalware.kb.a.991
MicrosoftTrojanDownloader:Win32/Loan.BG!MTB
ArcabitTrojan.Heur.E48D3F
ZoneAlarmTrojan.Win32.Agent.ilde
GDataWin32.Trojan.PSE.10GYYCV
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5605735
ALYacGen:Trojan.Heur.cuY@HPIO3zfb
MAXmalware (ai score=87)
VBA32Trojan.Sdter
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingDropper.Agent!1.E3CA (CLASSIC)
YandexTrojan.GenAsa!aOeY2HHrzOs
SentinelOneStatic AI – Malicious PE
MaxSecureDownloader.W32.Loan.a
FortinetW32/Agent.SOI!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Loan.BG!MTB

How to remove Trojan.Win32.Agent.ilde?

Trojan.Win32.Agent.ilde removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment