Trojan

Win32/TrojanDownloader.Agent.HNK removal instruction

Malware Removal

The Win32/TrojanDownloader.Agent.HNK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.HNK virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Win32/TrojanDownloader.Agent.HNK?


File Info:

name: 8C368861D029E08EA3D4.mlw
path: /opt/CAPEv2/storage/binaries/a260058b957ff41ba5eb69dae77715f940b6c8fe6f78bb95a524f2fe24f0e9d7
crc32: 1CE854E1
md5: 8c368861d029e08ea3d445be5a1684f3
sha1: c2580d4c5c3c2edca598ee81bdc0526fb24232d1
sha256: a260058b957ff41ba5eb69dae77715f940b6c8fe6f78bb95a524f2fe24f0e9d7
sha512: 6e05bc48ee089c903375446fbf1f65da6fafefb454cb33527e3d6ed567749e375c49320815718860764e42c22fd54f0b1e4061fa9d81279b9d13ba150cd2927c
ssdeep: 196608:7FUrL/fU0FgAhA4AvlWpm6wVsKYNQsUE81v5nqYuSdWQEt7TcRNC:qnUugAyzvlWs6IsUpqYukF4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3B63342E4C86CA0D51036323AE8EED9F46EBC0BB45CBB855F726D5605D70CA866F2D3
sha3_384: 0bb48dfce70c9defa3a72c50e7db2df0c5ccab336281e69cd435bf037d1f78c25b612e0ae31f4bbb87b68789158435e3
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.HNK also known as:

AVGNSIS:DropperX-gen [Drp]
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Suspicious.vc
McAfeeArtemis!8C368861D029
MalwarebytesPUP.Optional.BundleInstaller.Generic
SangforDownloader.Win32.Agent.Vrkx
AlibabaTrojanDownloader:Win32/OffLoader.b5f86045
K7GWTrojan-Downloader ( 005b1fcf1 )
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDownloader.Agent.HNK
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
AvastNSIS:DropperX-gen [Drp]
F-SecureHeuristic.HEUR/AGEN.1373316
Trapminemalicious.high.ml.score
SophosMal/Generic-S
AviraHEUR/AGEN.1373316
Antiy-AVLGrayWare/Win32.Wacapew
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.OffLoader.gen
VBA32BScope.Trojan.Packed
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07CI24
TencentWin32.Trojan-Downloader.Oader.Eflw
IkarusTrojan.Win32.OffLoader
FortinetW32/Agent.HNK!tr.dldr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/OffLoader.gen

How to remove Win32/TrojanDownloader.Agent.HNK?

Win32/TrojanDownloader.Agent.HNK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment