Trojan

Should I remove “Win64/TrojanDownloader.Agent.IY”?

Malware Removal

The Win64/TrojanDownloader.Agent.IY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/TrojanDownloader.Agent.IY virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win64/TrojanDownloader.Agent.IY?


File Info:

crc32: 9A4DD5FE
md5: 0a31ae5882697455a071f73191ed661c
name: 0A31AE5882697455A071F73191ED661C.mlw
sha1: 06c4e2c9a71dcada5dc6c090263df05bbdbd7e7e
sha256: fbeef8381db0c3c66d5646d8f2820ff08029f703d1891e490a102a3e8cdd1936
sha512: 18fcbf06a9c3158f2eb52df990e75ccdb6270663e37a02d712e76bbf04511f84b87589da9f58772efb1f2ddde64652655a3c3e520e84dcaede0d91f8d433e99e
ssdeep: 3072:0E5lmxpxrGySdgzfZYfuX9nW1amC6Yvbt7GPrLcj0qVqEiV8Io3rbq:0rxGySdMEuX9MamC6Yx7Esj7qJVS3rb
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: CONHOST.EXE
FileVersion: 10.0.19041.546
CompanyName: Microsoft
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.19041.546
FileDescription: x63a7x5236x53f0x7a97x53e3x4e3bx8fdbx7a0b
OriginalFilename: CONHOST.EXE
Translation: 0x0409 0x04b0

Win64/TrojanDownloader.Agent.IY also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36454273
FireEyeGeneric.mg.0a31ae5882697455
ALYacTrojan.GenericKD.36454273
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36454273
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.882697
CyrenW64/Trojan.VFZZ-3272
SymantecW97M.Downloader
AvastWin64:Malware-gen
KasperskyTrojan.Win64.Miner.amld
AlibabaTrojanDownloader:Win64/Miner.525b9e3a
RisingDownloader.Agent!8.B23 (CLOUD)
Ad-AwareTrojan.GenericKD.36454273
SophosMal/Generic-S
ComodoMalware@#cudm6rgue82k
F-SecureTrojan.TR/Dldr.Agent.yvlbq
DrWebTrojan.BtcMine.3531
McAfee-GW-EditionBehavesLike.Win64.Fake.cc
MaxSecureTrojan.Malware.300983.susgen
EmsisoftTrojan-Downloader.Agent (A)
IkarusTrojan-Downloader.Win64.Agent
AviraTR/Dldr.Agent.yvlbq
MAXmalware (ai score=97)
KingsoftWin32.Troj.Win64.am.(kcloud)
MicrosoftProgram:Win32/Ymacco.AAFB
GridinsoftMalware.Win64.Gen.oa
ArcabitTrojan.Generic.D22C3F81
AhnLab-V3Trojan/Win32.Miner.C4368625
ZoneAlarmTrojan.Win64.Miner.amld
GDataTrojan.GenericKD.36454273
CynetMalicious (score: 100)
ESET-NOD32Win64/TrojanDownloader.Agent.IY
McAfeeRDN/Generic Downloader.x
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
APEXMalicious
TencentWin64.Trojan-downloader.Agent.Eyb
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_96%
FortinetPossibleThreat.MU
AVGWin64:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win64/Heur.Generic.H8oAnVsA

How to remove Win64/TrojanDownloader.Agent.IY?

Win64/TrojanDownloader.Agent.IY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment