Malware

Application.Agent.ATT removal tips

Malware Removal

The Application.Agent.ATT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.ATT virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Agent.ATT?


File Info:

name: C353B0316487B22623AD.mlw
path: /opt/CAPEv2/storage/binaries/6a85d71415c1d045281619128daa6adb45bb1c5156858187d39c4536098ac9c6
crc32: FDD3A4EC
md5: c353b0316487b22623adba205d94f270
sha1: 6c532d1731fea262a0f984352252325c1dbcd5e6
sha256: 6a85d71415c1d045281619128daa6adb45bb1c5156858187d39c4536098ac9c6
sha512: 4718ce0e12f2f919ed61a52a1185ce2f25d72ddf40a4f05a799d62b9ffd58da951c46e524be143c5f635889de6eb0803c983c9238ca797c8fca3631a6e18687f
ssdeep: 24576:LUbIaDWwJ41fE5nWVIwwgjrRByjrYw0zbw2QKkUtV:LUbIaYCPQj9ByPYw0zfQMt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1212523827B8A09E7DA36B8F1794909549B106E350EC41D6B2674731C15FD393EE283EF
sha3_384: ff33ae97e2a4e8a727dbb22288331dd096faf58e6dbbc6fb078d447685c30286dec2d965ffe742e61f3587872d420c24
ep_bytes: 60be007062008dbe00a0ddffc78734dc
timestamp: 2013-03-28 14:49:26

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Application.Agent.ATT also known as:

BkavW32.Common.7C6FDC15
Elasticmalicious (moderate confidence)
DrWebAdware.Downware.10461
MicroWorld-eScanApplication.Agent.ATT
FireEyeGeneric.mg.c353b0316487b226
CAT-QuickHealPUA.Wedownload1.Gen
SkyhighDownloader-FMA
McAfeeDownloader-FMA
Cylanceunsafe
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/Generic.8b9f0523
K7GWAdware ( 004b99fc1 )
K7AntiVirusAdware ( 004b99fc1 )
VirITWorm.Win32.Siggen.MBP
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Soft32Downloader.C potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Downloadware-14
Kasperskynot-a-virus:AdWare.Win32.DownloadWare.bv
BitDefenderApplication.Agent.ATT
NANO-AntivirusTrojan.Win32.Soft32Downloader.dwzawx
SUPERAntiSpywareAdware.Siggen/Variant
AvastWin32:Downloader-TOV [PUP]
RisingPUF.Soft32Downloader!1.9C52 (CLASSIC)
EmsisoftApplication.Downloader (A)
F-SecureAdware.ADWARE/Ocna.fszgw
TrendMicroTROJ_GEN.R002C0OAP24
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Adkor
JiangminAdWare/DownloadWare.al
WebrootTrojan.Dropper.Gen
VaristW32/Soft32Download.A.gen!Eldorado
AviraADWARE/Ocna.fszgw
Antiy-AVLGrayWare[AdWare]/Win32.DownloadWare
Kingsoftmalware.kb.b.818
MicrosoftPUABundler:Win32/Soft32Downloader
XcitiumApplication.Win32.Agent.S@51hhun
ArcabitApplication.Agent.ATT
ViRobotAdware.Soft32Downloader.984704.AJS
ZoneAlarmnot-a-virus:AdWare.Win32.DownloadWare.bv
GDataWin32.Application.Soft32Downloader.A
GoogleDetected
AhnLab-V3Adware/Win32.DownloadWare.C193917
ALYacApplication.Agent.ATT
MAXmalware (ai score=99)
VBA32AdWare.DownloadWare
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OAP24
TencentAdware.Win32.DL.c
YandexTrojan.GenAsa!y0zbtb5KUu0
FortinetW32/Generic.AC.1BD95D!tr
AVGWin32:Downloader-TOV [PUP]
DeepInstinctMALICIOUS

How to remove Application.Agent.ATT?

Application.Agent.ATT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment