Malware

Python/Agent.GB removal guide

Malware Removal

The Python/Agent.GB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Agent.GB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

Related domains:

quwa-paf.servehttp.com

How to determine Python/Agent.GB?


File Info:

crc32: AE6AA7BD
md5: 6a271282fe97322d49e9692891332ad7
name: 6A271282FE97322D49E9692891332AD7.mlw
sha1: 0710e5b2432f18b181b404b87097fd8f61438f43
sha256: 35118d4ed995388333e3bcd09e9981f1006bf81ab54ab54b4f6be028fde948b2
sha512: 41a9a986f79b523024a9c0877116d11d5d02f093ddf58b873f577bc1f44e3b4871a49b146efa6d8e1c04514cafeab13ef0ac6d08617a94866de69d1aed0d09b0
ssdeep: 98304:RmISvdBAEoDCqpSlPLeqNZ8hY/wTSo5QAXZx7Sn4ScWsYjTQJ:BUxCz0lPKQ8hY/gSSQ+xIcWsoTQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Python/Agent.GB also known as:

BkavW32.AIDetectGBM.malware.02
Elasticmalicious (high confidence)
DrWebPython.BackDoor.76
MicroWorld-eScanTrojan.GenericKD.44558093
ALYacBackdoor.MSIL.SpyGate
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.44558093
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PKJ20
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Agent.mytqvc
AlibabaBackdoor:Win32/Python.b2904c36
NANO-AntivirusTrojan.Win32.Generic.gillmo
AvastFileRepMalware
TencentWin32.Backdoor.Agent.Wogd
Ad-AwareTrojan.GenericKD.44558093
SophosMal/Generic-S
F-SecureBackdoor.BDS/Agent.rjooq
TrendMicroTROJ_GEN.R002C0PKJ20
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.6a271282fe97322d
EmsisoftTrojan.GenericKD.44558093 (B)
IkarusTrojan.Python.Spy
MaxSecureTrojan.Malware.74641831.susgen
AviraBDS/Agent.rjooq
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Generic.D2A7E70D
AegisLabTrojan.Win32.Crypren.tpW3
ZoneAlarmBackdoor.Win32.Agent.mytqvc
GDataTrojan.GenericKD.44558093
CynetMalicious (score: 100)
McAfeeArtemis!6A271282FE97
MAXmalware (ai score=82)
VBA32Backdoor.Agent
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
ESET-NOD32Python/Agent.GB
YandexTrojan.Agent!jKOS93FSwZw
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.MYTQVC!tr.bdr
AVGFileRepMalware
Cybereasonmalicious.2fe973
Qihoo-360Win32/Backdoor.Generic.HgIASOcA

How to remove Python/Agent.GB?

Python/Agent.GB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment