Malware

How to remove “Application.Agent.KKE”?

Malware Removal

The Application.Agent.KKE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.KKE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Application.Agent.KKE?


File Info:

name: 52EAAF28637566DBC3DE.mlw
path: /opt/CAPEv2/storage/binaries/8d5e218f3c70a3da0862e5784b13a144d4aff71c1a0843518114d5fb4cbc2a9d
crc32: 39BFE521
md5: 52eaaf28637566dbc3de1b6aea698aee
sha1: 26c3748423bfdce160ce6288bc23313e72708185
sha256: 8d5e218f3c70a3da0862e5784b13a144d4aff71c1a0843518114d5fb4cbc2a9d
sha512: 1d8c769338b08b78c28c60dceb1344bdd82cfae81fc1110e805fbbeecf1a104caefb766057c1a3a19d16995affc2900084f801b332f5da1def4a691332e1cd77
ssdeep: 98304:8qeEadHQSj2olG461o7tnFn5/wEBf0m+S+O72:8XjV7tnb/Bf0m+RP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E265C23E641C867F165013045B727387F79B3B60EA49A93BF98CDF02F56221ABD664C
sha3_384: 80f63cdcf65ad8d3586aed8fdc60c640c2e83d19b58fdb2738266cfd390bccada8ddafc7431546cc102146d8cbf1cdc8
ep_bytes: 558bec6aff6830e2840068841e650064
timestamp: 2022-02-26 16:20:05

Version Info:

FileVersion: 43.1.0.1
FileDescription: www.luokexf.com
ProductName: 洛克王国旋风辅助
ProductVersion: 43.1.0.1
CompanyName: 洛克王国旋风辅助
LegalCopyright: 洛克王国旋风辅助 官网:www.luokexf.com 邮箱:admin@luokexf.com
Comments: www.luokexf.com
Translation: 0x0804 0x04b0

Application.Agent.KKE also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Agent.2!c
tehtrisGeneric.Malware
MicroWorld-eScanApplication.Agent.KKE
FireEyeGeneric.mg.52eaaf28637566db
CAT-QuickHealPUA.AgentRI.S27067672
McAfeeArtemis!52EAAF286375
CylanceUnsafe
SangforAdware.Win32.Agent.gen
K7AntiVirusTrojan ( 005246d51 )
AlibabaAdWare:Win32/FlyStudio.a0fefdd7
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.423bfd
BitDefenderThetaGen:NN.ZexaF.34606.@t0aaybYAafb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CBR22
Paloaltogeneric.ml
ClamAVWin.Trojan.Benban-9840578-0
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderApplication.Agent.KKE
AvastWin32:Adware-gen [Adw]
Ad-AwareApplication.Agent.KKE
EmsisoftApplication.Agent.KKE (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
ZillyaAdware.Agent.Win32.171733
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
SophosGeneric PUA CG (PUA)
APEXMalicious
GDataApplication.Agent.KKE
JiangminAdware.Agent.auof
MAXmalware (ai score=74)
Antiy-AVLTrojan/Generic.ASCommon.FA
ViRobotTrojan.Win32.Z.Agent.4759552.DB
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Agent.R484450
VBA32Adware.Agent
ALYacApplication.Agent.KKE
MalwarebytesTrojan.MalPack.FlyStudio
RisingAdware.Agent!8.71 (CLOUD)
YandexPUA.Agent!DltTaHNaLEU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Adware-gen [Adw]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Agent.KKE?

Application.Agent.KKE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment