Malware

About “Python/Agent_AGen.J” infection

Malware Removal

The Python/Agent_AGen.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Agent_AGen.J virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Python/Agent_AGen.J?


File Info:

name: 2F26EB62AE8BB4C6980E.mlw
path: /opt/CAPEv2/storage/binaries/1e523c54838f50effde3ce0e808f0448ca74a994ac71de7c35f5915c66645ea7
crc32: 03ECEEED
md5: 2f26eb62ae8bb4c6980e5ebb31b9b758
sha1: 2c234ffd9f5aa50a1f177019c7dddbeb8036d58a
sha256: 1e523c54838f50effde3ce0e808f0448ca74a994ac71de7c35f5915c66645ea7
sha512: 70bce0db2c70282077e5c843e696c804ac6d58b1fbb4e0c62d0faeab0ebc74f2e9884f494728d59ea3875c0f453688e8c7b1e20236501550f7c3275132d02434
ssdeep: 3072:XAsftqUS5ecpkCf9bp7SL4SnlJl0FW76JNz52I:ntqUcu29bp7SL4SnlJl0FW76JNzn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10804D6564E5ACCD9D2434DB445AA443BD2B9983DC9AB2407FF332E58EE372C47A1F290
sha3_384: 138f4fcb624dcbef52c43fddee5b7cf9f1f390616ad589bc0fb28787e691b89718dd11b5967c298f1e98f7ee0c08ea46
ep_bytes: 5589e583ec18c745f4ff000000c705bc
timestamp: 2023-01-06 22:46:18

Version Info:

CompanyName: Sherie
ProductVersion: 1.2.0.0
FileVersion: 1.2.0.0
OriginalFilename: main.exe
InternalName: main
ProductName: main
FileDescription: main.exe
Translation: 0x0000 0x04b0

Python/Agent_AGen.J also known as:

BkavW32.Common.6BB03A2F
LionicTrojan.Win32.Redcap.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.71637200
FireEyeTrojan.GenericKD.71637200
SkyhighBehavesLike.Win32.Generic.cm
McAfeeArtemis!2F26EB62AE8B
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.AgentAGen.Script.114
AlibabaTrojan:Win32/Redcap.67523f1b
Cybereasonmalicious.2ae8bb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Python/Agent_AGen.J
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.71637200
EmsisoftTrojan.GenericKD.71637200 (B)
F-SecureTrojan.TR/Redcap.uqtkw
VIPRETrojan.GenericKD.71637200
SophosGeneric Reputation PUA (PUA)
MAXmalware (ai score=84)
GoogleDetected
AviraTR/Redcap.uqtkw
VaristW32/ABTrojan.RSSY-8409
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D44518D0
GDataTrojan.GenericKD.71637200
CynetMalicious (score: 99)
VBA32BScope.Trojan.Bingoml
ALYacTrojan.GenericKD.71637200
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CBK24
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.Python.Agent
MaxSecureTrojan.Malware.233650085.susgen
FortinetW32/Agent_AGen.J!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Python/Agent_AGen.J?

Python/Agent_AGen.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment