Trojan

Trojan:WinNT/AgentHide.D malicious file

Malware Removal

The Trojan:WinNT/AgentHide.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:WinNT/AgentHide.D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:WinNT/AgentHide.D?


File Info:

name: 8D5B3D13C6A2D68CE32F.mlw
path: /opt/CAPEv2/storage/binaries/1d5b386db9e5ea6568fd0224921e526731e9c71d944c2371db97503270827521
crc32: C2266B8D
md5: 8d5b3d13c6a2d68ce32f272eaad9c8d4
sha1: 508af763a29586705ea38b6b3cc03f684eef26cc
sha256: 1d5b386db9e5ea6568fd0224921e526731e9c71d944c2371db97503270827521
sha512: b2802198dd32817f04a4f4b1ae25ed29495e36de8f2dc30862871bfb95e7e0ce7c40d2bb385bfd4ceeb36bca399d773c4673f82f0e6e5c4916290d0227cad05d
ssdeep: 48:qjtUDqs0KmQK2ZoEO1r0QZrPsTsTsTsW0p1yDmX2J5VwgbV7TgP:UtUDtdK2uEO1AQFT0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F51A706AFA05206C05D82B1110F3B7AB6755120363BAB26FFAC428C1C0B756B86330F
sha3_384: 6b2c4a84152af58ad7b57635428d786cfbaa1fbebcd9b2a297c69c99bcc49d863da2760c139eeebe1f51a2019a30e2ff
ep_bytes: 68dc040100e85a0200008b44240859c7
timestamp: 2007-03-06 17:49:02

Version Info:

0: [No Data]

Trojan:WinNT/AgentHide.D also known as:

LionicTrojan.Win32.Rootkit.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanRootkit.Zlob.A
FireEyeGeneric.mg.8d5b3d13c6a2d68c
SkyhighArtemis!Trojan
McAfeeArtemis!8D5B3D13C6A2
Cylanceunsafe
ZillyaTrojan.Vapsup.Win32.500
SangforRootkit.Win32.Vapsup.Vyj0
K7AntiVirusTrojan ( 000f91b21 )
AlibabaTrojan:Win32/Vapsup.96aa945a
K7GWTrojan ( 000f91b21 )
VirITTrojan.Win32.Agent.ARM
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.JVJNIUL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Rootkit-37
KasperskyTrojan.Win32.Vapsup.c
BitDefenderRootkit.Zlob.A
NANO-AntivirusTrojan.Win32.Vapsup.cedow
AvastWin32:RootkitX-gen [Rtk]
RisingRootkit.Generic!8.7D6 (TFE:2:ycbbNe10OHJ)
EmsisoftRootkit.Zlob.A (B)
F-SecureTrojan.TR/Rootkit.Gen
DrWebAdware.Videocatch
VIPRERootkit.Zlob.A
TrendMicroADW_RKPROC.AT
SophosTroj/RKProc-Fam
Ikarusnot-a-virus:AdWare.Win32.Agent
JiangminRootkit.Vanti.c
WebrootW32.Trojan.Downloader-Zlob
VaristW32/Rootkit.C.gen!Eldorado
AviraTR/Rootkit.Gen
Antiy-AVLTrojan/Win32.Vapsup
Kingsoftmalware.kb.a.998
MicrosoftTrojan:WinNT/AgentHide.D
XcitiumTrojWare.Win32.Vapsup.C@1bezvh
ArcabitRootkit.Zlob.A
ViRobotAdware.Agent.2944.A
ZoneAlarmTrojan.Win32.Vapsup.c
GDataRootkit.Zlob.A
GoogleDetected
AhnLab-V3Trojan/Win32.Vapsup.R75614
VBA32BScope.Trojan.Vapsup
ALYacRootkit.Zlob.A
MAXmalware (ai score=100)
PandaTrj/Cimuz.EC
TrendMicro-HouseCallADW_RKPROC.AT
TencentWin32.Trojan.Vapsup.Ymhl
YandexAdware.Agent!m5tUDAzShu4
FortinetMalware_fam.gw
AVGWin32:RootkitX-gen [Rtk]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:WinNT/AgentHide.D?

Trojan:WinNT/AgentHide.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment