Malware

Application.Agent.KEE removal instruction

Malware Removal

The Application.Agent.KEE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.KEE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Application.Agent.KEE?


File Info:

name: E60FD95FDF840F64CABA.mlw
path: /opt/CAPEv2/storage/binaries/e68a8c6ae95752fa6a7553e7f5b1855d05277d6eca048e23f6e119f0e82c194a
crc32: 41AA1E31
md5: e60fd95fdf840f64caba3ff165498623
sha1: edb3eb39503548bd49d294de80a57ec211be3398
sha256: e68a8c6ae95752fa6a7553e7f5b1855d05277d6eca048e23f6e119f0e82c194a
sha512: ab3e8851c19815e018c78a082ef221f56a8890971a5ede9ea1b40863d37fb99f4100d953c43e126c664577e0682c6b91535132878f45211996d520e608f8c7bd
ssdeep: 49152:vZt2X9bC7Ra3b7lWYRlG4jQbbgwFEFm4IzdtcAAJlwEBYnFWzmE1Sitmyc/0+0S8:A33l/RlG4jLLFeRt3AJlwEBC0m+SnjG5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC264B23E681C862F128013051B727387E75B3760BB1AB53FB98DCF56F53221AB9665C
sha3_384: 5e6af98f4c49b9850ed6c993ecdba808ff0411ae5958cd077e111e06fce21564e19711ef8b9f2bbffec212bb781bac18
ep_bytes: 558bec6aff6878a9820068a473630064
timestamp: 2021-11-05 12:23:22

Version Info:

FileVersion: 41.9.0.1
FileDescription: www.luokexf.com
ProductName: 洛克王国旋风辅助
ProductVersion: 41.9.0.1
CompanyName: 洛克王国旋风辅助
LegalCopyright: 洛克王国旋风辅助 官网:www.luokexf.com 邮箱:admin@luokexf.com
Comments: www.luokexf.com
Translation: 0x0804 0x04b0

Application.Agent.KEE also known as:

LionicTrojan.Win32.Generic.lq8W
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Agent.KEE
FireEyeGeneric.mg.e60fd95fdf840f64
CAT-QuickHealTrojan.IgenericRI.S19154072
ALYacApplication.Agent.KEE
CylanceUnsafe
SangforAdware.Win32.Agent.gen
K7AntiVirusTrojan ( 005246d51 )
AlibabaAdWare:Win32/FlyStudio.235c657a
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Benban-9840578-0
BitDefenderApplication.Agent.KEE
AvastWin32:MiscX-gen [PUP]
Ad-AwareApplication.Agent.KEE
EmsisoftApplication.Agent.KEE (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
ZillyaAdware.Agent.Win32.169696
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
SophosMal/Generic-S (PUA)
SentinelOneStatic AI – Malicious PE
GDataApplication.Agent.KEE
JiangminAdware.Agent.asqe
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.RL_Agent.R366133
Acronissuspicious
McAfeeArtemis!E60FD95FDF84
MAXmalware (ai score=76)
VBA32Adware.Agent
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H0CKA21
RisingTrojan.Woreflint!8.F5EA (CLOUD)
YandexPUA.Agent!B/ECKTgzV3E
IkarusTrojan-Dropper.Agent
eGambitGeneric.Malware
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34232.@t0aaGYkHhab
AVGWin32:MiscX-gen [PUP]
Cybereasonmalicious.950354
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Application.Agent.KEE?

Application.Agent.KEE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment