Trojan

Trojan:Win32/Malgent (file analysis)

Malware Removal

The Trojan:Win32/Malgent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Malgent virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Malgent?


File Info:

name: DAE9B9BE81EC79730E8B.mlw
path: /opt/CAPEv2/storage/binaries/cd0505435274d362c8577c8caa3a98d0067933cbc88f6068237e096fc3ccd176
crc32: 5188BA27
md5: dae9b9be81ec79730e8bf784b5c5b7b2
sha1: 1f0016c7e22896b12f295122dfffa2315e06d740
sha256: cd0505435274d362c8577c8caa3a98d0067933cbc88f6068237e096fc3ccd176
sha512: 026e2b49194c139246e4ecd5a097b46cf7993a8a05ebb733323de0c40c7c073c0b53c93c8722eb021b6c88edf91af6026811ab878896b39c93fde7c078d9a735
ssdeep: 3072:yrI6RZk0KW0unPfr6wjGNgcIL6RZk0KWzuTaAqY:yZLlPfr6wfELGbq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11285407D7120C03AF3927BF5B55BCC703A8A675C21251AFF260EDD916226D29E8B27C4
sha3_384: 784127450de1338ea1a5a2a0cc0914eaf14a50fab607324dd680cca3cc3a740966d211df54c994933185fa9a6bd2d4fa
ep_bytes: ff250020400000000000000000000000
timestamp: 2066-11-09 20:21:49

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: HT Client
FileVersion: 4.4.3.6
InternalName: HT Client.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: HT Client.exe
ProductName: HT Client
ProductVersion: 4.4.3.6
Assembly Version: 2.2.5.4

Trojan:Win32/Malgent also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47475268
FireEyeTrojan.GenericKD.47475268
CAT-QuickHealTrojan.WacatacFC.S19436270
McAfeeGenericRXOV-LC!DAE9B9BE81EC
ZillyaDownloader.Agent.Win32.455161
K7AntiVirusTrojan-Downloader ( 0057cfa41 )
AlibabaTrojan:MSIL/Agentb.9769fd16
K7GWTrojan-Downloader ( 0057cfa41 )
CyrenW32/MSIL_Troj.BAT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HYJ
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
KasperskyHEUR:Trojan.MSIL.Agentb.gen
BitDefenderTrojan.GenericKD.47475268
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Trojan-downloader.Agent.Wvkr
Ad-AwareTrojan.GenericKD.47475268
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionGenericRXOV-LC!DAE9B9BE81EC
SentinelOneStatic AI – Suspicious PE
EmsisoftTrojan.GenericKD.47475268 (B)
APEXMalicious
GDataTrojan.GenericKD.47475268
AviraTR/Dldr.Agent.pgnqj
Antiy-AVLTrojan/Generic.ASMalwS.34D70F2
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Win.1719808
MicrosoftTrojan:Win32/Malgent
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.C4414862
ALYacTrojan.GenericKD.47475268
MAXmalware (ai score=84)
MalwarebytesMalware.AI.4076787947
YandexTrojan.Agentb!mGZRkGaGksQ
IkarusTrojan-Downloader.MSIL.Agent
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.HYJ!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan:Win32/Malgent?

Trojan:Win32/Malgent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment