Malware

VHO:AdWare.Win32.Agent malicious file

Malware Removal

The VHO:AdWare.Win32.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:AdWare.Win32.Agent virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VHO:AdWare.Win32.Agent?


File Info:

crc32: 331567C6
md5: 7f24803c299d0f1a00977346b52cc9ed
name: 7F24803C299D0F1A00977346B52CC9ED.mlw
sha1: 7318ecd1736a0268674509f85af37c7426e40210
sha256: 5d4659a32bbd9e002661f713f5a2e143afd81d436a61311502647275245f85a8
sha512: b09c8b7d2c7d14d7c68991143660f83208e3a7dd31db781364232a786cf3b3424747459920fc612d89e9e16d65b68317deecf40427a19541c3069a6cedab9d3a
ssdeep: 49152:uBSmEajuOKZBkB3rfW/KSsvvZ05TS7ItTa:zMjBKZ2ZRHZ0xS7ItTa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: This is a free program, please do not use for commercial purposes. This program is completely for lovers to study and research! Any consequences caused by anyone using this program have nothing to do with the author!
FileVersion: 1.0.0.0
CompanyName: Yulgang Network Room
Comments: Network Send & Save
ProductName: Yulgang Network
ProductVersion: 1.0.0.0
FileDescription: Yulgang Network
Translation: 0x0804 0x04b0

VHO:AdWare.Win32.Agent also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f54a1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Flyagent.af2ff6b8
K7GWTrojan ( 0040f54a1 )
Cybereasonmalicious.1736a0
CyrenW32/A-2521f541!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Pasta [Cryp]
Kasperskynot-a-virus:VHO:AdWare.Win32.Agent.gen
NANO-AntivirusVirus.Win32.Agent.dvixmz
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34686.3r0@ae!TlPcb
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7f24803c299d0f1a
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
MicrosoftProgram:Win32/Wacapew.C!ml
Acronissuspicious
McAfeeFlyagent.d
MalwarebytesTrojan.MalPack.FlyStudio
PandaGeneric Suspicious
RisingPacker.Win32.Agent.g (CLASSIC)
IkarusPUA.PUPStudio
FortinetW32/CoinMiner.BELF!tr
AVGWin32:Pasta [Cryp]
Paloaltogeneric.ml

How to remove VHO:AdWare.Win32.Agent?

VHO:AdWare.Win32.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment