Malware

Hoax.Win32.Agent removal

Malware Removal

The Hoax.Win32.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Hoax.Win32.Agent virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Hoax.Win32.Agent?


File Info:

name: C9F11E5D63980AEA6F28.mlw
path: /opt/CAPEv2/storage/binaries/dcc8ec4b606dcc8422320dff8da952e5509a0521c0bff209d7b596c66e8f7877
crc32: 3B732CEB
md5: c9f11e5d63980aea6f281789f9dbe359
sha1: 9d28ab9b40d94012244b9937c5e5993c93d4c53a
sha256: dcc8ec4b606dcc8422320dff8da952e5509a0521c0bff209d7b596c66e8f7877
sha512: fb30091cccb2d14551aa626d07edeea9ebd5eba20763fba1f2605e59b18f00e017ef6923c3c7f06e945a5b54b6fb88313230dd2d16fd5785fa0bbb60d8abdd9a
ssdeep: 1536:Wxkzy48untU8fOMEI3jyYfPiuORuGj9sEN:nzltUeOsaPuGj9sEN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10083EA4EFAA922F1CEC745F8142A7821D3D3BE29135047EB06CC3552E7A8BE1C67652D
sha3_384: 3931b367fd3a7d9c7f89cd43ad160fabf036939b5ddba91e6cc7bd67b440f11884885de41803faf5fded0c07392a933f
ep_bytes: 6800010000680000000068d8e34000e8
timestamp: 2016-10-27 16:06:34

Version Info:

CompanyName: Scanvec
FileVersion: 1,0,0,0
ProductName: Flexisign
ProductVersion: 1.0.0.0
LegalCopyright: www.signs101.com
Translation: 0x0000 0x04e4

Hoax.Win32.Agent also known as:

BkavW32.AIDetectMalware
AVGWin32:Malware-gen
MicroWorld-eScanTrojan.GenericKD.72474782
SkyhighBehavesLike.Win32.Dropper.mh
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTool.Agent.Win32.141905
SangforSuspicious.Win32.Save.a
VirITBackdoor.Win32.Generic.CNLA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32BAT/Agent.QBP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Hoax-10017823-0
KasperskyHoax.Win32.Agent.gen
BitDefenderTrojan.GenericKD.72474782
NANO-AntivirusVirus.Win32.Sality.bgiylc
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.kbv
EmsisoftTrojan.GenericKD.72474782 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBAT.Siggen.250
VIPRETrojan.GenericKD.72474782
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c9f11e5d63980aea
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Daws.fyt
VaristW32/Trojan.OTMT-9114
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Occamy
Kingsoftmalware.kb.a.766
MicrosoftTrojan:Win32/Lazy.AB!MTB
ArcabitTrojan.Generic.D451E09E
ZoneAlarmVHO:Hoax.Win32.Agent.gen
GDataWin32.Trojan.PSE.13TFRNA
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36804.fC2@aOGzgah
ALYacTrojan.GenericKD.72474782
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Occamy!8.F1CD (TFE:5:GPpcP9MuPnT)
IkarusTrojan.Tiggre
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/BAT.OBP!tr
ZonerTrojan.Win32.64771
DeepInstinctMALICIOUS

How to remove Hoax.Win32.Agent?

Hoax.Win32.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment