Malware

About “Win32:Agent-HIH [Wrm]” infection

Malware Removal

The Win32:Agent-HIH [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Agent-HIH [Wrm] virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:Agent-HIH [Wrm]?


File Info:

name: 1685ABC82029B6D705FF.mlw
path: /opt/CAPEv2/storage/binaries/93567514b5227ea71c2fcad0cbe531ff4e43446ca85e2e86fc9e8cda84ea129a
crc32: 9D1F9C1F
md5: 1685abc82029b6d705ff48aa39525a09
sha1: 261540345c75f1bc9beff9c891dfa48d71ad2909
sha256: 93567514b5227ea71c2fcad0cbe531ff4e43446ca85e2e86fc9e8cda84ea129a
sha512: d6d5e410336ff1311e98d0622ec25a398b949ed550ac93e2c7de7d55bd6721476009f4ff482add60286cf2fcfe4b079bde1eef1863f7bbd8cd247e044ee5e2a8
ssdeep: 196608:q07lhv4+zaZK4DT81o3LAKmP0R/7pS2E5RV9BYb3mnSdK/zvwpyFl1v6psjLmoa:N7zxzaZKt1o3IP0RsLRVk4fFl1v6pQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184D62303F04285B5FA7506324DD22A345B22F68A6D224F4F7748DE59AD23351FA3B36E
sha3_384: 957d7f87dca9f87bccafa5de0d42428478829951b0e65a6306a6b007cfa18cab0ce603dfcd29e2186aee2f06196caf78
ep_bytes: 6888500700c300000000000000000000
timestamp: 2024-03-26 10:14:42

Version Info:

FileVersion: 1.0.0.0
FileDescription: By-瓜皮Tuza
ProductName: 绝地卢本伟同款自瞄
ProductVersion: 1.0.0.0
CompanyName: QQ:1344895492
LegalCopyright: QQ:1344895492 版权所有
Comments: explorer.exe
Translation: 0x0804 0x04b0

Win32:Agent-HIH [Wrm] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Agent.o!c
AVGWin32:Agent-HIH [Wrm]
Elasticmalicious (high confidence)
FireEyeGeneric.mg.1685abc82029b6d7
SkyhighBehavesLike.Win32.Generic.rc
McAfeeArtemis!1685ABC82029
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
AlibabaTrojan:Win32/Cerber.e2a1b587
BitDefenderThetaGen:NN.ZexaF.36802.@F0@aeG9f!db
VirITBackdoor.Win32.Pigeon.DRAN
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Disabler.NCO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Bingd-1
KasperskyUDS:Worm.Win32.Agent.xwm
AvastWin32:Agent-HIH [Wrm]
TencentMalware.Win32.Gencirc.10bfa42e
BaiduWin32.Trojan-Dropper.Agent.e
F-SecureMalware.VBS/Agent.098
DrWebBackDoor.Pigeon.64233
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.17UBEGE
VaristW32/KillAV.AU.gen!Eldorado
AviraVBS/Agent.098
Antiy-AVLRiskWare/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftTrojan:Win32/Cerber.MPI!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.R641668
VBA32BScope.Trojan.Bitrep
Cylanceunsafe
RisingTrojan.Disabler!1.BB16 (CLASSIC)
IkarusTrojan.Win32.Krypt
FortinetW32/CoinMiner.2438!tr
ZonerProbably Heur.ExeHeaderL
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Multi/VBS.A

How to remove Win32:Agent-HIH [Wrm]?

Win32:Agent-HIH [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment