Trojan

Should I remove “Trojan.Win32.Agent.nevyre”?

Malware Removal

The Trojan.Win32.Agent.nevyre is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.nevyre virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Disables Windows firewall
  • The sample wrote data to the system hosts file.
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Agent.nevyre?


File Info:

name: 54F65CB07E482BB35FCD.mlw
path: /opt/CAPEv2/storage/binaries/05b4e96d84e3a26fb5e88d45f440bdc430ae21d29a31efa25de6ea636a13cceb
crc32: 0345E5AC
md5: 54f65cb07e482bb35fcd34eee8759636
sha1: a4fac74cbd57fcefca6156b1cbcc516c1a5f058c
sha256: 05b4e96d84e3a26fb5e88d45f440bdc430ae21d29a31efa25de6ea636a13cceb
sha512: 5e85957e43aa8a0d2a07468be2012feb2c0e0db600209dee833baf1e47f054b48ca2cf103afdb98ea01a5f4ec6b7a93f8396ea3c8e1817c257a7134c2dbe406e
ssdeep: 768:H1NAUsbxtT6sFst/3IrdlLUw5nbcuyD7UIb:H1NAUwtT6sFstwrbUcnouy8Ib
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15BB2D052E6EE4E35E35B127EA98FBB3A0B50710FD9744B9256D8302F0C55B84DC3A272
sha3_384: 23f2a1dd812c8cb6e86747b9b2f72acda20452d3127a85bf920cf7054885998bfa759ec53c445679c20892722210ab3e
ep_bytes: 60be15b040008dbeeb5fffff5789e58d
timestamp: 2009-02-07 06:33:02

Version Info:

CompanyName: Google
FileVersion: 17,0,0,0
ProductName: Google Chrome 17 Beta
ProductVersion: 17,0,0,0
LegalCopyright: Google Inc. 2011
Translation: 0x0000 0x04e4

Trojan.Win32.Agent.nevyre also known as:

CynetMalicious (score: 99)
McAfeeArtemis!54F65CB07E48
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004b9c8e1 )
K7GWUnwanted-Program ( 004b9c8e1 )
VirITTrojan.Win32.Cryptic.BDO
SymantecTrojan.Gen.2
ESET-NOD32BAT/HostsChanger.A potentially unsafe
APEXMalicious
ClamAVWin.Trojan.Agent-840498
KasperskyTrojan.Win32.Agent.nevyre
NANO-AntivirusTrojan.Win32.KillProc.obybr
AvastFileRepMalware [Trj]
RisingTrojan.Agent!8.B1E (CLOUD)
ComodoSuspicious@#1myfvkhb7vr1a
DrWebTrojan.KillProc.10562
Webrootw32.malware.gen
AviraTR/AD.BatServStopper.lzqzw
MicrosoftTrojan:Win32/Wacatac.B!ml
TencentWin32.Trojan.Agent.bgeo
MaxSecureTrojan.Malware.300983.susgen
FortinetBAT/KillWin.NES!tr
AVGFileRepMalware [Trj]
PandaGeneric Malware

How to remove Trojan.Win32.Agent.nevyre?

Trojan.Win32.Agent.nevyre removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment