Malware

Troj/Agent-BEXC removal tips

Malware Removal

The Troj/Agent-BEXC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-BEXC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

skillters.top
apps.identrust.com
isrg.trustid.ocsp.identrust.com
groston.top
ocsp.int-x3.letsencrypt.org

How to determine Troj/Agent-BEXC?


File Info:

crc32: D030374A
md5: e3072bed157b289566a6ac3c0e78dd6d
name: tmpw3v1gybq
sha1: abc18fd602e6720d9483d9239461437c2ef57992
sha256: 6f928f4fbc26ab5f66731151402064c11b014cda036c35bc827f95f218d1cd3a
sha512: f9c9c66aa22b7c3c8f9e020af035345a055609a115561f78880d39b4e16e454d6157dcc7d68a0a9cb569a2ad824d2e16ec605ba9425dd401280da751e0d1eb7c
ssdeep: 6144:xJNurpEchSxUL25sVpmKy2vNckX5D8CUzrs/pouMs18jV8DKQ+4Cg+rD:LuThSGLEK6MD/yw/poTVWNC
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Agent-BEXC also known as:

MicroWorld-eScanGen:Variant.Razy.685874
FireEyeGeneric.mg.e3072bed157b2895
McAfeeGenericRXKZ-FG!E3072BED157B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.685874
K7GWTrojan ( 0056891e1 )
K7AntiVirusTrojan ( 0056891e1 )
CyrenW32/S-3fb680aa!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
GDataGen:Variant.Razy.685874
KasperskyHEUR:Trojan-Spy.Win32.Gazvas.vho
NANO-AntivirusTrojan.Win32.Kryptik.hlbqtu
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgPi/xzCWxBeWg)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.685874 (B)
F-SecureTrojan.TR/Crypt.Agent.vvktf
McAfee-GW-EditionGenericRXKZ-FG!E3072BED157B
SophosTroj/Agent-BEXC
F-ProtW32/S-3fb680aa!Eldorado
AviraTR/Crypt.Agent.vvktf
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Razy.DA7732
ZoneAlarmHEUR:Trojan-Spy.Win32.Gazvas.vho
MicrosoftTrojan:Win32/Gazvas.DEA!MTB
CynetMalicious (score: 85)
VBA32Trojan.Wacatac
ALYacGen:Variant.Razy.685874
Ad-AwareGen:Variant.Razy.685874
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEAE
TencentMalware.Win32.Gencirc.10cdd567
YandexTrojan.Kryptik!BLfcy/Y1qaU
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.HEAE!tr
BitDefenderThetaGen:NN.ZedlaF.34128.sq5@aKnETHb
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM40.1.F559.Malware.Gen

How to remove Troj/Agent-BEXC?

Troj/Agent-BEXC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment