Trojan

Trojan.Agent.BOND (file analysis)

Malware Removal

The Trojan.Agent.BOND is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BOND virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Libya)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.BOND?


File Info:

crc32: ADEE4609
md5: 2cafc37c092db4362830df66cd7aa44f
name: 2CAFC37C092DB4362830DF66CD7AA44F.mlw
sha1: 8282e175d71ef94d5ff443cf4176e5964541f9d4
sha256: 76c319a3da9d92ac2d69f99f97562b7d38be62efbf5da69c81b3c23d716d91a7
sha512: 6ccc77bb416d3a00210bd020f73106150f171d97fd6ff0830d3f15a38702ef455c0e80f0fb854fbbf7aff8ee593ed839ebd3d3778fb8f3b426b9a6be8aabe648
ssdeep: 6144:p+UivvEq6VDiAW3reShVJznXFwEyjQQAygBK6Jyd5:M53EBVOUYVwVjQ1c6O5
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Perchance (C) 2017
InternalName: Salmon
FileDescription: Replays
OriginalFilename: Sentencing.exe
CompanyName: Supper Rabbit

Trojan.Agent.BOND also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.59570
CynetMalicious (score: 100)
CAT-QuickHealRansom.Tescrypt.A4
ALYacTrojan.Agent.BOND
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.1473
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/TeslaCrypt.0533a39f
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.c092db
BaiduWin32.Trojan.Filecoder.k
CyrenW32/Ransom.OZYG-7019
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:TeslaCrypt-P [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BOND
NANO-AntivirusTrojan.Win32.AVKill.dyxvnh
ViRobotTrojan.Win32.TeslaCrypt.Gen.B
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.Agent.BOND
TencentMalware.Win32.Gencirc.10c50195
Ad-AwareTrojan.Agent.BOND
SophosMal/Generic-R + Troj/Ransom-BQO
ComodoTrojWare.Win32.Tescrypt.DS@66xxh2
BitDefenderThetaGen:NN.ZexaF.34628.uq0@ayF@!XnG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SM
McAfee-GW-EditionPWSZbot-FAOG!2CAFC37C092D
FireEyeGeneric.mg.2cafc37c092db436
EmsisoftTrojan.Agent.BOND (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.dcr
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1123567
eGambitUnsafe.AI_Score_97%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Tescrypt!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Agent.BOND
TACHYONTrojan/W32.Yakes.327680.D
Acronissuspicious
McAfeePWSZbot-FAOG!2CAFC37C092D
MAXmalware (ai score=100)
VBA32Trojan.Yakes
PandaTrj/CryptoWall.C
TrendMicro-HouseCallRansom_CRYPTESLA.SM
RisingTrojan.Ransom-Tesla!1.A322 (CLOUD)
YandexTrojan.Yakes!xJi3eGZwsP0
IkarusTrojan.Win32.Filecoder
FortinetW32/TeslaCrypt.I!tr
AVGWin32:TeslaCrypt-P [Trj]
Qihoo-360Win32/Ransom.Bitman.HxQBEpsA

How to remove Trojan.Agent.BOND?

Trojan.Agent.BOND removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment