Malware

Application.Agent.GCB removal instruction

Malware Removal

The Application.Agent.GCB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.GCB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

node1.installtraffic.com
ocsp.usertrust.com
ocsp.comodoca.com
ocsp.verisign.com

How to determine Application.Agent.GCB?


File Info:

crc32: 32BB1902
md5: d681ccdff2c401cd35c307562c02f7d1
name: LoviVideoSetupRU.exe
sha1: fe78166ef10c69c6d9d78a5d4287ba28dab1543f
sha256: bb6913f894822d7ff75ad100b8ba7a13299aa16e2bdc36fa54d642470bb956ad
sha512: 80db8ce9ef4b63233a4a0cc97049c407fc82857f0c78e5f8f75b544991b260dae678f7cfbc5836b30de4ed35dd0933f7b0f6ee00b77523d390eca20b6e53ca02
ssdeep: 196608:U76ti1qbOH4/Ozk0LMLufkDEf4URNSgllNOJOSx5GPRdGnX:4oskGk0LMKPAUXSgllsBu4X
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2004-2015 !TVA LLC.
InternalName: Installer
FileVersion: 1.2.1.0
CompanyName: !TVA LLC
LegalTrademarks: !TVA, InstallTraffic.
ProductName: Product Installer
ProductVersion: 1.2.1.0
FileDescription: !TVA Software Installer
OriginalFilename: Installer.exe
Translation: 0x0409 0x04e4

Application.Agent.GCB also known as:

BkavW32.HfsAdware.41D7
MicroWorld-eScanApplication.Agent.GCB
McAfeeArtemis!D681CCDFF2C4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004c34cd1 )
BitDefenderApplication.Agent.GCB
K7GWAdware ( 004c34cd1 )
TrendMicroPUA_ITVA_FD120156.UVPA
APEXMalicious
ClamAVWin.Malware.Agent-6376266-0
GDataApplication.Agent.GCB
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.gen
AlibabaAdWare:Win32/Generic.c6c69d6c
AegisLabAdware.Win32.Generic.2!c
RisingDownloader.Banload!8.15B (CLOUD)
Endgamemalicious (moderate confidence)
SophosGeneric PUA PO (PUA)
ComodoApplication.Win32.Itva.DE@6ay9sf
F-SecurePotentialRisk.PUA/Itva.Gen7
DrWebAdware.Downware.11337
ZillyaAdware.Amonetize.Win32.13259
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.d681ccdff2c401cd
IkarusPUA.Itva
JiangminAdware.Agent.aivy
WebrootPua.Gen
AviraPUA/Itva.Gen7
eGambitUnsafe.AI_Score_93%
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftPUA:Win32/Itva
ArcabitApplication.Agent.GCB
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Agent.gen
AhnLab-V3PUP/Win32.Amonetize.R180087
VBA32Adware.Downware
MalwarebytesPUP.Optional.BundleInstaller
ESET-NOD32Win32/Itva.E potentially unwanted
TrendMicro-HouseCallPUA_ITVA_FD120156.UVPA
TencentMalware.Win32.Gencirc.10b0f24d
YandexRiskware.Agent!
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Itva
AVGFileRepMalware
Cybereasonmalicious.ff2c40
Paloaltogeneric.ml

How to remove Application.Agent.GCB?

Application.Agent.GCB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment