Trojan

Trojan.Win32.Agent.zmse (file analysis)

Malware Removal

The Trojan.Win32.Agent.zmse is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.zmse virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Trojan.Win32.Agent.zmse?


File Info:

name: 69696C85ABF71544F831.mlw
path: /opt/CAPEv2/storage/binaries/0b9a8b25d5c461c3a8ea94afef20baa4c7c84822ba8b23c4301238f645dccb4e
crc32: 5C7D5F86
md5: 69696c85abf71544f831425c959326b7
sha1: 8caade1a5cff2660bfc03c9f700bbb793d654622
sha256: 0b9a8b25d5c461c3a8ea94afef20baa4c7c84822ba8b23c4301238f645dccb4e
sha512: 22c6ad07dc26db0b096285988685705908a846c5f677bbb363bb370a331453387e7470236d021da90c615fbeb183d0a1d58be7cf7d34794f5b36b813457a2563
ssdeep: 1536:0jgUBotV2PCLlGrENtBhecFcukzpAlRWRxQX:fUB82PCMoNpDlKAlRCxQX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17064E51DAAFF001BE45DC2B42FC0E87F4894E73725A5AD342DD84BDA0B58D4479DA23A
sha3_384: dc30e993d0fdc27f490bfa64b0e8a50625fdb7c9c09b7ccb64d6fc149c494de5777e682c4a4d52ae1adae53dd3623285
ep_bytes: 6838184000e8f0ffffff000000000000
timestamp: 2011-08-13 08:19:39

Version Info:

Translation: 0x0409 0x04b0
Comments: LrABzEpiqThgwAC
CompanyName: adsNOYidGVpIc
FileDescription: lSkVaAomgyvRoMR
LegalCopyright: qhuFonbMoK
ProductName: LVqEreEbaC
FileVersion: 1.00
ProductVersion: 1.00
InternalName: video
OriginalFilename: video.exe

Trojan.Win32.Agent.zmse also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.ManBat.1
FireEyeGeneric.mg.69696c85abf71544
CAT-QuickHealTrojan.VB.Gen
ALYacGen:Heur.ManBat.1
CylanceUnsafe
VIPREGen:Heur.ManBat.1
K7AntiVirusTrojan ( 0054ec131 )
K7GWTrojan ( 0054ec131 )
Cybereasonmalicious.5abf71
CyrenW32/VBKrypt.BHG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.HKF
APEXMalicious
KasperskyTrojan.Win32.Agent.zmse
BitDefenderGen:Heur.ManBat.1
NANO-AntivirusTrojan.Win32.CFI.jsguna
AvastWin32:Inject-ALI [Trj]
TencentTrojan.Win32.Sabsik.ha
Ad-AwareGen:Heur.ManBat.1
EmsisoftGen:Heur.ManBat.1 (B)
ZillyaTrojan.Injector.Win32.1582256
McAfee-GW-EditionGenericRXUL-DY!69696C85ABF7
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.ManBat.1
JiangminTrojan.Generic.hmmqn
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Generic.ASMalwS.51F4
ArcabitTrojan.ManBat.1
MicrosoftTrojan:Script/Phonzy.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Malco.R7759
Acronissuspicious
McAfeeGenericRXUL-DY!69696C85ABF7
MAXmalware (ai score=88)
VBA32BScope.Trojan.VB.01559
MalwarebytesMalware.AI.2791285831
RisingHackTool.VBInject!1.6481 (CLASSIC)
YandexTrojan.Agent!D+tWQGMk8iQ
IkarusTrojan.Win32.Injector
MaxSecureTrojan.W32.Multi.Generic
FortinetW32/Injector.HKF!tr
BitDefenderThetaGen:NN.ZevbaF.34754.tm1@aCr2Q@bi
AVGWin32:Inject-ALI [Trj]
PandaTrj/GdSda.A

How to remove Trojan.Win32.Agent.zmse?

Trojan.Win32.Agent.zmse removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment