Malware

Application.Agent.IAT (B) removal tips

Malware Removal

The Application.Agent.IAT (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.IAT (B) virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Agent.IAT (B)?


File Info:

name: 00BB568F20AD22278F42.mlw
path: /opt/CAPEv2/storage/binaries/d3797f0b4784dec1aa5c3c2311a8377bb9091bea62b40ec5e2bbcdbdb889bf9e
crc32: A9F67C9D
md5: 00bb568f20ad22278f4237303cb70a7c
sha1: aa22c4e9b0e435a19ea77a8bc811ef231679ef38
sha256: d3797f0b4784dec1aa5c3c2311a8377bb9091bea62b40ec5e2bbcdbdb889bf9e
sha512: 5e6f77d1b8e13e266be906e8997546151549a6ddcb19d67d08183331eec3742c700956ab8bcf51bae9dfa10452609b3164a8481e1ad14a11e21d6e8b26723edb
ssdeep: 12288:usM+aTA3c+FK1vrlVYBVignBtZnfVq4cz1i5pP9kPQC:lV4W8hqBYgnBLfVqx1WjkP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1613517316AC18031D3123331CE14EEEE356A6DB40DDA955FE2A43B394BB41B2DD3B65A
sha3_384: e4c04c244b9af0afc66925419b1532180e0969c51ff7aba7bfa70807af9a6a9fbaf7bd5a5e4f1a59bdbac705a1ecb4e8
ep_bytes: e829070000e98efeffff558bec5de9a8
timestamp: 2017-11-22 08:45:43

Version Info:

CompanyName: Cloud Installer
FileDescription: IESettings
FileVersion: 4, 2, 0, 8
InternalName: IESettings
LegalCopyright: Copyright (C) 2017 Cloud Installer
OriginalFilename: IESettings
ProductName: IESettings
ProductVersion: 4, 2, 0, 8
Translation: 0x0409 0x04b0

Application.Agent.IAT (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DnsChange.8272
MicroWorld-eScanApplication.Agent.IAT
ClamAVWin.Trojan.Fam-6454574-1
FireEyeApplication.Agent.IAT
CAT-QuickHealTrojan.Startpage.S1656376
ALYacApplication.Agent.IAT
MalwarebytesGeneric.Malware.AI.DDS
ZillyaAdware.Agent.Win32.136467
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00533fc91 )
AlibabaMalware:Win32/km_2c606d0.None
K7GWAdware ( 00533fc91 )
Cybereasonmalicious.f20ad2
VirITPUP.Win32.CloudInstaller.A
CyrenW32/StartPage.CN.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.Agent.bahf
BitDefenderApplication.Agent.IAT
NANO-AntivirusTrojan.WinXX.StartPage.esqohz
SUPERAntiSpywareTrojan.Agent/Gen-StartPage
AvastWin32:AdwareSig [Adw]
TencentTrojan.Win32.Startpage.abv
SophosCloudWrapper (PUA)
VIPREApplication.Agent.IAT
TrendMicroTROJ_GEN.R002C0OEQ23
McAfee-GW-EditionBehavesLike.Win32.PUPXFU.tm
EmsisoftApplication.Agent.IAT (B)
SentinelOneStatic AI – Malicious PE
GDataApplication.Agent.IAT
JiangminTrojan.StartPage.cpn
MAXmalware (ai score=71)
Antiy-AVLTrojan/Win32.StartPage.a
XcitiumApplication.Win32.StartPage.NSS@7ai7rr
ArcabitApplication.Agent.IAT
ViRobotAdware.StartPage.1130488.BFJ
ZoneAlarmnot-a-virus:RiskTool.Win32.Agent.bahf
MicrosoftPUA:Win32/Spigot
GoogleDetected
AhnLab-V3PUP/Win32.StartPage.R213772
McAfeePUP-XFU-JI
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OEQ23
RisingAdware.Agent!1.ADA9 (CLASSIC)
YandexTrojan.GenAsa!KZoO4r7Rzvc
IkarusPUA.Agent
MaxSecureHEUR:Trojan.Win32.StartPage
FortinetPossibleThreat.DU
AVGWin32:AdwareSig [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Application.Agent.IAT (B)?

Application.Agent.IAT (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment