Trojan

Should I remove “Win32/TrojanDownloader.Agent.FVH”?

Malware Removal

The Win32/TrojanDownloader.Agent.FVH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.FVH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Oman)
  • Looks up the external IP address
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to disable Windows Defender
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

cdn.discordapp.com
ocsp.digicert.com
ipinfo.io
iplis.ru
apps.identrust.com

How to determine Win32/TrojanDownloader.Agent.FVH?


File Info:

crc32: 24B15151
md5: 543ed8a17f16ce5b16b7c33702111dbf
name: 543ED8A17F16CE5B16B7C33702111DBF.mlw
sha1: 8a15f59cbc26b424cea2da8c8ca21fd1b468dc83
sha256: b54dffe48f5ddc423d5f292363b29d5143e6f0f54120aea3208e067faff45457
sha512: 1d2068576cbe68ceec5a0cedda70e666fd50595f2c5ccad90631640d5371cb5107d128e1da2f84ad67dbcb909161688a0a0f3010a2bf7305af9ec97b44590358
ssdeep: 12288:pktZEyufdBGp4MAuVEaRtyncxQRhJJzhoqgH5sB4dxHG64:6tZoGp/HRhQRh9B4d3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021 BlueRates
InternalName: BlueRates.exe
FileVersion: 101.7.10.1
CompanyName: BlueRates
ProductName: BlueRates
ProductVersion: 101.7.10.1
FileDescription: BlueRates
OriginalFilename: BlueRates.exe
Translation: 0x0009 0x04b0

Win32/TrojanDownloader.Agent.FVH also known as:

CynetMalicious (score: 100)
CylanceUnsafe
Cybereasonmalicious.cbc26b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FVH
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyUDS:DangerousObject.Multi.Generic
MicroWorld-eScanGen:Variant.Bulz.668871
BitDefenderThetaGen:NN.ZexaF.34126.av0@aq6NgFkO
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.th
FireEyeGen:Variant.Bulz.668871
EmsisoftGen:Variant.Bulz.668871 (B)
eGambitUnsafe.AI_Score_53%
MicrosoftTrojan:Win32/Azorult!ml
GDataGen:Variant.Bulz.668871
AhnLab-V3Dropper/Win.Mudrop.C4611786
McAfeeArtemis!543ED8A17F16
MAXmalware (ai score=82)
VBA32BScope.Trojan.Sabsik.FL
PandaTrj/Genetic.gen
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Win32/TrojanDownloader.Agent.FVH?

Win32/TrojanDownloader.Agent.FVH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment