Ransom Trojan

VHO:Trojan-Ransom.MSIL.Agent information

Malware Removal

The VHO:Trojan-Ransom.MSIL.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Ransom.MSIL.Agent virus can do?

  • Network activity detected but not expressed in API logs

How to determine VHO:Trojan-Ransom.MSIL.Agent?


File Info:

crc32: 4102979B
md5: 6c55d22137018cd1c8a8791dbed630f6
name: 6C55D22137018CD1C8A8791DBED630F6.mlw
sha1: 42a1effb789ec9138f4d6b339099363a89f2d7f8
sha256: a0bc9b7720ce09872186c004d237bfe156a9e0c6c67468e21d9515add243fec1
sha512: b6d6cdd89847f6e8320cabc05459232ea476c59e108845bb94fde23cc56356b939990ed2eb7a3158c485ebae12b156eb3b63e68974f733b958f14ed23a2a6ed6
ssdeep: 3072:Kygi6zch3OXMt8idi9vP9Ar0dwumkGI9jC30ndY:h6wh3S9idixP9DdwumkGIOSd
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 2019 JlXkcIDIgH5z
Assembly Version: 4.5.0.0
InternalName: iWOFBhDnbXzG
FileVersion: 4.5.0.0
CompanyName: bsHRv66rOEpj vWMQDVdtp0wd
LegalTrademarks: b6fsslspVdpm SFLQ13yk6oIK
ProductName: uBDa9fVPlVmd
ProductVersion: 4.5.0.0
FileDescription: Memory Operator
OriginalFilename: zuBDHGHp5vRX

VHO:Trojan-Ransom.MSIL.Agent also known as:

Elasticmalicious (high confidence)
DrWebTrojan.EncoderNET.31368
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.6.Gen
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.MSIL.Basic.6.Gen
Cybereasonmalicious.137018
CyrenW32/MSIL_Thanos.A.gen!Eldorado
ESET-NOD32a variant of MSIL/Filecoder.Thanos.A
APEXMalicious
KasperskyVHO:Trojan-Ransom.MSIL.Agent.gen
MicroWorld-eScanTrojan.MSIL.Basic.6.Gen
Ad-AwareTrojan.MSIL.Basic.6.Gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34738.im0@aCWeHQc
TrendMicroRansom.MSIL.THANOS.SM
McAfee-GW-EditionRansom-Thanos!6C55D2213701
FireEyeGeneric.mg.6c55d22137018cd1
EmsisoftTrojan.MSIL.Basic.6.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1139814
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:MSIL/Thanos.DC!MTB
ArcabitTrojan.MSIL.Basic.6.Gen
GDataTrojan.MSIL.Basic.6.Gen
AhnLab-V3Malware/Win32.RL_Generic.C4192539
McAfeeRansom-Thanos!6C55D2213701
MAXmalware (ai score=81)
TrendMicro-HouseCallRansom.MSIL.THANOS.SM
IkarusTrojan-Ransom.Thanos
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Thanos.A!tr.ransom

How to remove VHO:Trojan-Ransom.MSIL.Agent?

VHO:Trojan-Ransom.MSIL.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment