Rootkit

VHO:Rootkit.Win32.Agent information

Malware Removal

The VHO:Rootkit.Win32.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Rootkit.Win32.Agent virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine VHO:Rootkit.Win32.Agent?


File Info:

name: 6E10EB87FC91CDBA016A.mlw
path: /opt/CAPEv2/storage/binaries/1649a393db7c29172b355a9f426f620bdc69e2be90dbfac57df7eb8420a429f0
crc32: 5E799677
md5: 6e10eb87fc91cdba016adad07fe2d467
sha1: b5ec6d104a6a5736e1077ca5ffc5ed9e49962f66
sha256: 1649a393db7c29172b355a9f426f620bdc69e2be90dbfac57df7eb8420a429f0
sha512: ba2ead19c4bf53dc140a0da190041717ca5b932006a0a4fb067190c9a74f2d731b14d684e46e77ace3b25586dc864395f5e75c74da0c6d22762c9729989de89c
ssdeep: 196608:nJXs2cfERqv6+skC+Pnc2xQVrfGtu6+skC:W2ceqLDZeVGi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B76AD22A042C0B0D82C097594B95738FD364BB139A6C967D7D0FEF6AD721206B6F35E
sha3_384: fddc84eb11397c9a6c545609d4492073a5022e90e1b3c09ab42a0efb040eea0cbb37a994a109e625d164760db333591d
ep_bytes: 558bec6aff686825aa006844b6490064
timestamp: 2021-11-22 01:54:38

Version Info:

0: [No Data]

VHO:Rootkit.Win32.Agent also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.6e10eb87fc91cdba
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaPacked:Win32/Blackv.97476aa4
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (D)
BaiduWin32.Packed.VMProtect.a
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:MiscX-gen [PUP]
ClamAVWin.Trojan.Black-9815930-0
KasperskyVHO:Rootkit.Win32.Agent.gen
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
DrWebTrojan.BtcMine.2446
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/VMProtBad-A
GDataWin32.Trojan.PSE.161Z26R
AviraTR/Black.Gen2
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C4687757
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34084.@xW@auHl5Idb
VBA32BScope.Backdoor.Poison
MalwarebytesTrojan.MalPack.FlyStudio
RisingTrojan.MalCert!1.D834 (CLASSIC)
SentinelOneStatic AI – Malicious PE
AVGWin32:MiscX-gen [PUP]
Cybereasonmalicious.04a6a5

How to remove VHO:Rootkit.Win32.Agent?

VHO:Rootkit.Win32.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment