Malware

Win32/Agent.SHT malicious file

Malware Removal

The Win32/Agent.SHT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.SHT virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
0.tcp.ngrok.io

How to determine Win32/Agent.SHT?


File Info:

crc32: DB68293F
md5: cb1fb51b5ef0bd2d17fb126fa42b870b
name: CB1FB51B5EF0BD2D17FB126FA42B870B.mlw
sha1: 5ff5d1629b29909fdbd10ec1709cf5de33b98f3d
sha256: 2662b93994a09fa4d02e24e566d16214be112e43cc135882483db21c5c4386d4
sha512: 1d69f56338593000548addad82d8e8e5b4b335bb0ce2d7737866e87c617744f02a54a9803344534e328dd05e1c0a6b095c71c6ae7dd34b0a1a5b3f6286b68e24
ssdeep: 12288:oxmIJQvPkitm5azNmvMSRMi8Bah9igsR3pq5XADs:GmoO8itm5az4vMSRMi8Bah9BqZeL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Agent.SHT also known as:

K7AntiVirusTrojan ( 002193031 )
DrWebTrojan.Click3.26538
ALYacTrojan.Rasftuby.Gen.14
CylanceUnsafe
SangforTrojan.Win32.Shelma.sb
K7GWTrojan ( 002193031 )
Cybereasonmalicious.b5ef0b
CyrenW32/Rozena.O.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Agent.SHT
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Shelma.sb
BitDefenderTrojan.Rasftuby.Gen.14
NANO-AntivirusTrojan.Win32.Click3.feuqup
MicroWorld-eScanTrojan.Rasftuby.Gen.14
TencentWin32.Trojan.Crypted.Sxyd
Ad-AwareTrojan.Rasftuby.Gen.14
SophosMal/Generic-S
ComodoMalware@#1lq0hhaz8e91b
BitDefenderThetaAI:Packer.CC5BE14C1E
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.gh
FireEyeGeneric.mg.cb1fb51b5ef0bd2d
EmsisoftTrojan.Rasftuby.Gen.14 (B)
SentinelOneStatic AI – Malicious SFX
AviraHIDDENEXT/Crypted
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Rasftuby.Gen.14
McAfeeArtemis!CB1FB51B5EF0
MAXmalware (ai score=98)
VBA32BScope.Trojan.Win64.Shelma
PandaTrj/CI.A
YandexTrojan.GenAsa!WwoTB51pKPY
IkarusTrojan.Win32.Veilev
FortinetW32/Agent.SHT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Agent.SHT?

Win32/Agent.SHT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment