Trojan

Should I remove “Win64/TrojanDownloader.Agent.NV”?

Malware Removal

The Win64/TrojanDownloader.Agent.NV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/TrojanDownloader.Agent.NV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Created a process from a suspicious location
  • A script process created a new process
  • Deletes executed files from disk

How to determine Win64/TrojanDownloader.Agent.NV?


File Info:

name: 9E8EDD37B67B29378A89.mlw
path: /opt/CAPEv2/storage/binaries/4323e82725d15a44b3283132b558809a9f1f7784ad2f6d98b921d8eecc0945e2
crc32: F7D4BAA3
md5: 9e8edd37b67b29378a898c5a0fae3f87
sha1: 8ee37fd7b67301a9d48743f246dfcd28c82ac6ca
sha256: 4323e82725d15a44b3283132b558809a9f1f7784ad2f6d98b921d8eecc0945e2
sha512: d5eb3f09a2418c567af06bf9028f3c43a54bda88bcedf69e832504a6f68893a6c6981bb742b894c96c20c60357ddf87e822fb201170f3b6eaf868c4c2cedc335
ssdeep: 49152:JbA301qkDsyLNOO7C+833T1oxjreJtPrGYj/5LxPu+lJEr/0:JbskDsfyC+83jIeJtPKYjbffS0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA9522027AD454B2D6B12A301AB47714253FBC700B78996FB3DC4DAD9B771D0AA227B3
sha3_384: 0ee64346a1fc3960ef922aa53245cfa0c9fa9665331afea8ad5c1caf6fdf9f5c9861e4634c5cb3539f5662661a4e75f4
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Win64/TrojanDownloader.Agent.NV also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.39894622
FireEyeGeneric.mg.9e8edd37b67b2937
McAfeeGenericRXAA-FA!9E8EDD37B67B
VIPRETrojan.GenericKD.39894622
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.7b6730
CyrenW64/ABRisk.LGXW-8490
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/TrojanDownloader.Agent.NV
ClamAVWin.Malware.Agen-9949363-0
KasperskyHEUR:Trojan-Dropper.Win32.Miner.gen
BitDefenderTrojan.GenericKD.39894622
APEXMalicious
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.39894622 (B)
IkarusTrojan.Scar
GDataTrojan.GenericKD.39894622
AviraHEUR/AGEN.1242193
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.7783
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R363526
Acronissuspicious
ALYacTrojan.GenericKD.39894622
MalwarebytesTrojan.Downloader
AvastWin64:DropperX-gen [Drp]
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
AVGWin64:DropperX-gen [Drp]

How to remove Win64/TrojanDownloader.Agent.NV?

Win64/TrojanDownloader.Agent.NV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment