Trojan

How to remove “Win32/TrojanDownloader.Agent.NGE”?

Malware Removal

The Win32/TrojanDownloader.Agent.NGE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.NGE virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking

How to determine Win32/TrojanDownloader.Agent.NGE?


File Info:

crc32: 7FF51222
md5: 50845772be3bfbf1dcc0f4aa7365069a
name: 50845772BE3BFBF1DCC0F4AA7365069A.mlw
sha1: dc41f533d1a3eec1be0587563112ee837dce81e0
sha256: f8f483ab933242a03e955da435461f4844729cb3a1c378379ec5897fe5416e27
sha512: 19cf786cc174a34a42269bd93f15a8914294a2b7faf0fbff6d1949182f7d284a398c8951b55cfc38c816ba10b389236e38ed292cbe477663741ed410e306c466
ssdeep: 384:iUHoiVaKR4Ggb78vx8aMibhypy08m9Bp7SaWk/Jh96lo:iUH5a5b78p8DilYR8CpunwJhB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.NGE also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Zlob.1.Gen
FireEyeGeneric.mg.50845772be3bfbf1
ALYacTrojan.Zlob.1.Gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Obfuscated.a!c
SangforMalware
K7AntiVirusTrojan ( 0040f8b51 )
BitDefenderTrojan.Zlob.1.Gen
K7GWTrojan ( 0040f8b51 )
Cybereasonmalicious.2be3bf
BaiduWin32.Trojan-Downloader.Agent.ir
CyrenW32/Downloader.YJVM-8732
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
ClamAVWin.Downloader.42534-1
KasperskyTrojan-Downloader.Win32.Obfuscated.aa
AlibabaTrojanDownloader:Win32/Obfuscated.0b142c75
NANO-AntivirusTrojan.Win32.Crypt.mxjz
ViRobotTrojan.Win32.Downloader.30492
TencentWin32.Trojan-downloader.Obfuscated.Stua
Ad-AwareTrojan.Zlob.1.Gen
SophosML/PE-A + Troj/Dloadr-AKJ
ComodoTrojWare.Win32.TrojanDownloader.Agent.NGE@2496
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.DownLoader.11346
ZillyaDownloader.Obfuscated.Win32.3360
TrendMicroTROJ_HORST.NZ
McAfee-GW-EditionBehavesLike.Win32.Dropper.mh
CMCGeneric.Win32.50845772be!MD
EmsisoftTrojan.Zlob.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Obfuscated.cui
WebrootW32.Backdoor.Gen
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan[Downloader]/Win32.Obfuscated
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojanDownloader:Win32/Small
ArcabitTrojan.Zlob.1.Gen
ZoneAlarmTrojan-Downloader.Win32.Obfuscated.aa
GDataTrojan.Zlob.1.Gen
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Horst.C69247
Acronissuspicious
McAfeegeneric!bg.ftt
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Horst
MalwarebytesMalware.Heuristic.1003
PandaTrj/Rizalof.JKH
ESET-NOD32Win32/TrojanDownloader.Agent.NGE
TrendMicro-HouseCallTROJ_HORST.NZ
RisingTrojan.DL.Win32.Agent.aiq (TFE:5:TjOEzEdF4dN)
YandexTrojan.GenAsa!KmmlnF+4yZc
IkarusTrojan-Proxy.Win32.Horst
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.218C6E!tr
BitDefenderThetaAI:Packer.4486508B1D
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Zlob.HwsBh4sA

How to remove Win32/TrojanDownloader.Agent.NGE?

Win32/TrojanDownloader.Agent.NGE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment