Trojan

Trojan.Win32.Agent.nevhtu removal

Malware Removal

The Trojan.Win32.Agent.nevhtu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.nevhtu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Turkish
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Agent.nevhtu?


File Info:

crc32: A98AB62B
md5: 314fb4735f8393ebde0cd5dfca2a9565
name: dwaynetcafeupdate01-04-2009.exe
sha1: 5f0a4fce65fc42c1a12c74d001f26df184ffe811
sha256: 4612c97cf391eb0693646ab6f8299989d9c4f3d8b4d0c2282df881bf985595d5
sha512: ae2230bfd160aecb6eeabc8e57985fe5867085b4d769f5c2653ba32df0518c51b1cba7fe1e694019d9dbd16d49919b5e0324d29ed860c3900ba840f960296770
ssdeep: 98304:cHBf4LJOIAMmgohs0X97pvUcc8mJn1EzsR7sOZz6zpWWyis2mEAU9Ir:cHh44IAMnEVpk8mJn1fR7jGzpfCEAoIr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1990-2002 InstallShield Software Corporation
InternalName: ISPNickel
FileVersion: 7, 01, 100, 1248
CompanyName: InstallShield Software Corporation
ProductName: InstallShield (R)
OLESelfRegister:
ProductVersion: 7, 01
FileDescription: InstallShield (R) Setup Launcher
OriginalFilename: Setup.exe
Translation: 0x0409 0x04b0

Trojan.Win32.Agent.nevhtu also known as:

Qihoo-360Win32/Trojan.524
McAfeeArtemis!314FB4735F83
SangforMalware
KasperskyTrojan.Win32.Agent.nevhtu
AlibabaTrojan:Win32/Generic.b8b872f7
AegisLabTrojan.Win32.Agent.4!c
TencentWin32.Trojan.Agent.Lgtr
McAfee-GW-EditionArtemis
IkarusTrojan.Agent
WebrootW32.Malware.Gen
ZoneAlarmTrojan.Win32.Agent.nevhtu
MicrosoftPUA:Win32/Presenoker
RisingTrojan.Agent!8.B1E (CLOUD)
AVGFileRepMalware

How to remove Trojan.Win32.Agent.nevhtu?

Trojan.Win32.Agent.nevhtu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment