Spy

BAT/Spy.Agent.CV information

Malware Removal

The BAT/Spy.Agent.CV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Spy.Agent.CV virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine BAT/Spy.Agent.CV?


File Info:

name: 6D9C179D9683F58748AD.mlw
path: /opt/CAPEv2/storage/binaries/e9e2e6bfd526de607b71c94d6a5f3e6749a3702d24b7e919a901a8d7f163600d
crc32: 0541E770
md5: 6d9c179d9683f58748ad399821755ca0
sha1: 5adc2f887e08761749dbe9e60d241d134f6462ba
sha256: e9e2e6bfd526de607b71c94d6a5f3e6749a3702d24b7e919a901a8d7f163600d
sha512: 54b162928bfe26367efb1b860892e23c7d0f721907698ff4393caac801755fa21dd38b6a4f574b4c86d7ce70d8644e8a301de5156798c0e0ec55661aa205745c
ssdeep: 1536:P7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfAwGu9x+IOu:j7DhdC6kzWypvaQ0FxyNTBfAhu9x+i
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A4A37D41F3E202F7EAF1093100A6766F973662389B24A8DBC74C2D525913AD5A63D3F9
sha3_384: f8c2a23476295505090eedbd1e0a6f23a0bdbd7be6cee8d75820e87c8cfb50e6ac4a3c790d451677ca77928e23ce443f
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

BAT/Spy.Agent.CV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
FireEyeGeneric.mg.6d9c179d9683f587
MalwarebytesTrojan.ZLoader
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00501e0c1 )
K7GWTrojan ( 00501e0c1 )
Cybereasonmalicious.87e087
ESET-NOD32BAT/Spy.Agent.CV
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AvastWin32:Trojan-gen
F-SecureMalware.BAT/Spy.Agent.kdvjc
McAfee-GW-EditionBehavesLike.Win32.RealProtect.nh
SophosMal/Generic-S (PUA)
GDataWin32.Trojan.Agent.SYSSH6
AviraBAT/Spy.Agent.kdvjc
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win.Generic.C4671477
McAfeeArtemis!6D9C179D9683
TrendMicro-HouseCallTROJ_GEN.R002H0ADU23
RisingTrojan.Generic@AI.97 (RDML:9I98GVY+K/tjb+iQeJVl0g)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.36164.guW@aqudiyi
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove BAT/Spy.Agent.CV?

BAT/Spy.Agent.CV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment