Trojan

VHO:Trojan-Downloader.Win32.Agent removal tips

Malware Removal

The VHO:Trojan-Downloader.Win32.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Downloader.Win32.Agent virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
mas.to
a.tomx.xyz

How to determine VHO:Trojan-Downloader.Win32.Agent?


File Info:

crc32: 16B43A83
md5: a473075391597a5385dbac578ad51c69
name: A473075391597A5385DBAC578AD51C69.mlw
sha1: e7f171824d049d2df0fd2e39e1c7ba352fbccd96
sha256: f2962bc483f62e359dca3b911e2b422bf057dec9a14c4863992ea063d5d960da
sha512: 5981de1e1de77d370b9acdf8d8b1383dc24b0114c0337b5a586f7495807517a7abcbbbb149206f3d722ccf014712bc39cf19c21471666e66f26632035f209dc7
ssdeep: 12288:9Z4yiUQfbUwsAFAs3sG5ESy5Kc7o2yM9a0L3J3JT:9Z45LbxXstP7VyM9a0LL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sojbmoiminu.ihe
ProductVersion: 8.79.590.38
Copyright: Copyrighz (C) 2021, fudkagata
Translation: 0x0129 0x0171

VHO:Trojan-Downloader.Win32.Agent also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CAT-QuickHealRansom.Stop.P5
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWHacktool ( 700007861 )
Cybereasonmalicious.24d049
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Downloader.Win32.Agent.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34170.Lq0@aqaExFlO
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.a473075391597a53
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Mokes.eny
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
McAfeePacked-GDT!A47307539159
VBA32BScope.Backdoor.MSIL.Agent
MalwarebytesMachineLearning/Anomalous.100%

How to remove VHO:Trojan-Downloader.Win32.Agent?

VHO:Trojan-Downloader.Win32.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment