Spy

Dropped:Generic.Spyagent.5.AB33687F removal tips

Malware Removal

The Dropped:Generic.Spyagent.5.AB33687F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Spyagent.5.AB33687F virus can do?

  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

ip-api.com
www.facebook.com
uehge4g6gh.2ihsfa.com
iplogger.org

How to determine Dropped:Generic.Spyagent.5.AB33687F?


File Info:

crc32: D2C43A4F
md5: b51e7d646f5a2019129e54c2854ff869
name: B51E7D646F5A2019129E54C2854FF869.mlw
sha1: 9f8a1a1efc22cd57ef09c9c4c4e9823e6916cecc
sha256: 3f1a77de98cae1062980c21a0968dbc94acd71c7cca507b401203a2e0b5ca96a
sha512: dcd382693241f63c6c3549edb56b63bbcf665dffeef08194b9a884fa651d4c622892ff1095883ad77ac6ac26aa85d896bec02c9d7ca2108a245e23cf64640ecb
ssdeep: 24576:m8POn8y6V8TiFR8/u0QupHN9PTNkdBAnlXG6+Z1mbXI6:Ap6V8TiFRl0DpHzhkUlXF+Z1IY6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Dropped:Generic.Spyagent.5.AB33687F also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Spyagent.5.AB33687F
FireEyeGeneric.mg.b51e7d646f5a2019
CAT-QuickHealTrojan.Vigua
McAfeeGenericRXAA-FA!B51E7D646F5A
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005723511 )
BitDefenderDropped:Generic.Spyagent.5.AB33687F
K7GWTrojan ( 005723511 )
Cybereasonmalicious.46f5a2
CyrenW32/Ursu.EB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.CookiesStealer.b
AlibabaTrojan:Win32/CookiesStealer.1c4c38e0
NANO-AntivirusTrojan.Win32.Ool.hqsnsl
AegisLabTrojan.Win32.CookiesStealer.4!c
RisingStealer.Facebook!1.CC5B (CLASSIC)
Ad-AwareDropped:Generic.Spyagent.5.AB33687F
EmsisoftDropped:Generic.Spyagent.5.AB33687F (B)
F-SecureTrojan.TR/Redcap.ahesa
DrWebTool.PassView.1944
TrendMicroTROJ_GEN.R002C0PLR20
McAfee-GW-EditionBehavesLike.Win32.PUP.dc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Fsysna.lpr
MaxSecureTrojan.Malware.7164915.susgen
AviraTR/Redcap.ahesa
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Agent.oa
ArcabitGeneric.Spyagent.5.AB33687F
ZoneAlarmTrojan.Win32.CookiesStealer.b
GDataDropped:Generic.Spyagent.5.AB33687F
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4224261
BitDefenderThetaGen:NN.ZexaF.34700.8uW@a0@lkvoj
ALYacDropped:Generic.Spyagent.5.AB33687F
VBA32BScope.Trojan.Infospy
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Agent.ACLN
TrendMicro-HouseCallTROJ_GEN.R002C0PLR20
TencentMalware.Win32.Gencirc.11b7fe41
YandexTrojan.Convagent!WP9TbZjCMq4
IkarusTrojan.Malagent
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.VHO!tr
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.9fd

How to remove Dropped:Generic.Spyagent.5.AB33687F?

Dropped:Generic.Spyagent.5.AB33687F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment