Malware

How to remove “AdWare.Win32.Agentb”?

Malware Removal

The AdWare.Win32.Agentb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Agentb virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine AdWare.Win32.Agentb?


File Info:

name: 1417FE07E602A806AD81.mlw
path: /opt/CAPEv2/storage/binaries/ce2cb3154f6db3bff5e3cd108c1bffe7677da09238b35a1358fd8702f43045de
crc32: 271B135F
md5: 1417fe07e602a806ad81d986aa0d7b16
sha1: d63c17edfc0455ef21d8c8c0602028225991137f
sha256: ce2cb3154f6db3bff5e3cd108c1bffe7677da09238b35a1358fd8702f43045de
sha512: f0aa59e12ec18ecf42845d2669232cc9dd717478b36fbddc23d29a21c8b432df006d731694ca32587fb004fa6761ee6605121012fe969e9850877aa8038c4556
ssdeep: 49152:pNB/4VSA8pQrOvvl1c6pqrIKCez7dXvcDVFsq04qs:J/4VSA8L3l2QqnCeNXvcDVFsqD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CB57D3279D1D07AC2331732DE4DB36962ADFF705A35434762953E2E2DF0493A9286A3
sha3_384: 3e52bd073b2af952ab8de79f079bfac4a04d4149201e383e3fcd0856f2e9bfb9dd5db9ea2945635ce1f0845cfb6cb7f5
ep_bytes: e81b700000e97ffeffff566a046a20e8
timestamp: 2021-07-16 12:57:47

Version Info:

CompanyName: MirxayzarAPCP Group
FileDescription: DriverInstallTool
FileVersion: 1.0.0.1
InternalName: DriverInstallTool.exe
LegalCopyright: Copyright MirxayzarAPCP Group (C) 2021
OriginalFilename: DriverInstallTool.exe
ProductName: DriverInstallTool
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

AdWare.Win32.Agentb also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.408629
FireEyeGen:Variant.Zusy.408629
ALYacGen:Variant.Zusy.408629
CylanceUnsafe
ZillyaAdware.PCAcceleratePro.Win32.998
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Agentb.5bfdd80a
K7GWAdware ( 0058ac451 )
K7AntiVirusAdware ( 0058ac451 )
CyrenW32/PCAccelerate.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.PCAcceleratePro.U.gen
TrendMicro-HouseCallTROJ_GEN.R03FC0WL321
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agentb.gen
BitDefenderGen:Variant.Zusy.408629
NANO-AntivirusRiskware.Win32.PCAccerleratePro.jipfes
AvastWin32:AdwareX-gen [Adw]
TencentMalware.Win32.Gencirc.10cf90b6
Ad-AwareGen:Variant.Zusy.408629
EmsisoftApplication.PCFixer (A)
TrendMicroTROJ_GEN.R03FC0WL321
McAfee-GW-EditionGenericRXQX-PF!1417FE07E602
SophosGeneric PUA NG (PUA)
IkarusPUA.PCAcceleratePro
GDataGen:Variant.Zusy.408629
JiangminAdWare.Agentb.j
AviraADWARE/PCAccerleratePro.kdimb
MAXmalware (ai score=87)
Antiy-AVLGrayWare[AdWare]/Win32.PCAcceleratePro
ViRobotAdware.Pcacceleratepro.2425568
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGenericRXQX-PF!1417FE07E602
VBA32Adware.Agentb
MalwarebytesPUP.Optional.PCAcceleratePro
YandexPUA.Agentb!K8AZqUhwwb4
FortinetRiskware/PCAcceleratePro
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A

How to remove AdWare.Win32.Agentb?

AdWare.Win32.Agentb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment