Trojan

Win32/TrojanDownloader.Agent.HIV removal

Malware Removal

The Win32/TrojanDownloader.Agent.HIV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.HIV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Agent.HIV?


File Info:

name: 56D887AC8FDB9E369A43.mlw
path: /opt/CAPEv2/storage/binaries/be500ecb39fd0400e11ab7086303847c6d026631348cfb65124664e44a008b74
crc32: 64C33C40
md5: 56d887ac8fdb9e369a434105dac0c069
sha1: 0904bd076a985e44cb6901da7456f9a717e8980d
sha256: be500ecb39fd0400e11ab7086303847c6d026631348cfb65124664e44a008b74
sha512: 091d82088bfbc2a26e07efefbb3cee59d62420ea4fc6dabd557cf3cb8cc24d823a23dcdcd7eeabf291f5a0ef2ec29bf351c4be81209a981214a76e4c40fe8af8
ssdeep: 24576:s7FUDowAyrTVE3U5F/uy7MKic6QL3E2vVsjECUAQT45deRV9R5:sBuZrEUfIKIy029s4C1eH9T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D75BF3FF268A13EC56A1B3245738320997BBA61B81A8C1E47FC344DCF765601E3B656
sha3_384: dae173eb7855b7733675df8992c9893f6df55c62d51016994f3c1de5140ae9a05b174be56a10f7ae80f59d6ef429303b
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: R-Undelete 65 Build 170927 Portable Disks and files SClou
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: R-Undelete 65 Build 170927 Portable Disks and files SClou
ProductVersion: 3.12
Translation: 0x0000 0x04b0

Win32/TrojanDownloader.Agent.HIV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OffLoader.a!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Trojan.tc
Cylanceunsafe
SangforDownloader.Win32.Offloader.V3y8
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/OffLoader.bb7bffc9
K7GWTrojan-Downloader ( 005ae0e11 )
K7AntiVirusTrojan-Downloader ( 005ae0e11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.HIV
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan-Downloader.Win32.OffLoader.agpp
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13f7fe4f
F-SecureTrojan.TR/Downloader.Gen
TrendMicroTrojan.Win32.OFFLOADER.USBLKP23
SophosMal/Generic-S
IkarusTrojan.Inno.Agent
VaristW32/Agent.HTI.gen!Eldorado
AviraTR/Downloader.Gen
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/OffLoader.EM!MTB
ZoneAlarmTrojan-Downloader.Win32.OffLoader.agpp
GDataWin32.Trojan.Agent.YU2FWL
GoogleDetected
McAfeeArtemis!56D887AC8FDB
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.OFFLOADER.USBLKP23
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.221025165.susgen
FortinetW32/Agent.HIV!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Win32/TrojanDownloader.Agent.HIV?

Win32/TrojanDownloader.Agent.HIV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment