Malware

About “Application.Agent.GEX” infection

Malware Removal

The Application.Agent.GEX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.GEX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Application.Agent.GEX?


File Info:

crc32: 5DAE8582
md5: e42d8bf0f8c16e0597d937f31d451a4e
name: yldfcxgq.exe
sha1: 267cd515a1a68f998de60c07f94c6b391a83de52
sha256: 47d2792b8a322c2aa8009e338e79b84488d6471a53c5709ac8dfa9d19be70ec6
sha512: 29bbcf46db3ddb8d6a76cd3f6087d17d4a5df2a9fc260eb5995c8a6d190915c860b9e17b66240f90efea3a5d8c4374e80279beaf115322e0cc254be6161418f3
ssdeep: 196608:xYJPo+b/hJRYGsDLbor7wqVmIVtl1HHK:S2+b/JY9DLborkqbJ1q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6797x6bdbx4e4bx5bb6x7248x6743x6240x6709
FileVersion: 2.80.12.1228
CompanyName: x6797x6bdb
Comments: x6b22x8fcex5149x4e34x6211x7684x8bbax575b:www.51wyx.net
ProductName: x7ea2x8272x8b66x62122x4feex6539x5927x5e08x7f
ProductVersion: 2.80.12.1228
FileDescription: x7ea2x8272x8b66x62122x4feex6539x5927x5e08x7f x63d0x4f9bx7ea2x8272x8b66x62122x5185x5b58x4feex6539x7684x529fx80fd
Translation: 0x0804 0x04b0

Application.Agent.GEX also known as:

MicroWorld-eScanApplication.Agent.GEX
CAT-QuickHealHackTool.Prepscram
McAfeeArtemis!E42D8BF0F8C1
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.XZ (v)
K7AntiVirusUnwanted-Program ( 004eb1401 )
K7GWUnwanted-Program ( 004eb1401 )
Cybereasonmalicious.0f8c16
ArcabitApplication.Agent.GEX
Invinceaheuristic
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Trojan.Agent-6323130-0
BitDefenderApplication.Agent.GEX
NANO-AntivirusTrojan.Win32.Agent.dgpydw
RisingTrojan.Generic@ML.96 (RDMK:MnkXJxJgIA48amqin4dzfQ)
Endgamemalicious (high confidence)
EmsisoftApplication.Agent.GEX (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
F-SecureTrojan.TR/Agent.7061504.1
TrendMicroTROJ_GEN.R002C0RIS19
McAfee-GW-EditionBehavesLike.Win32.LoadMoney.vc
FortinetW32/FlyStudio_HackTool.A
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e42d8bf0f8c16e05
SophosMal/VMProtBad-A
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
MAXmalware (ai score=72)
MicrosoftSoftwareBundler:Win32/Prepscram
Acronissuspicious
Ad-AwareApplication.Agent.GEX
TrendMicro-HouseCallTROJ_GEN.R002C0RIS19
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_80%
GDataApplication.Agent.GEX
WebrootW32.Malware.Gen
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Agent.GEX?

Application.Agent.GEX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment