Trojan

What is “Trojan.Agent.CBTY”?

Malware Removal

The Trojan.Agent.CBTY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CBTY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Trojan.Agent.CBTY?


File Info:

name: 1DAF679D166FBBD23BAC.mlw
path: /opt/CAPEv2/storage/binaries/94222f16a1568dcc3071e1d41f9c757c2ad050ecdb1ffe9cb2f83d1012b6d5c0
crc32: 241896CA
md5: 1daf679d166fbbd23bac7b50c2f2cae1
sha1: 08ea1198cd7e191607c3ae9fe9f6ca6150dab999
sha256: 94222f16a1568dcc3071e1d41f9c757c2ad050ecdb1ffe9cb2f83d1012b6d5c0
sha512: a83825bc127dc9e198cca8ff3cab1dc210058ee02d2494eadb03d6dfb392edca35c943d08fc9626efbd3bd1fe68642bebbb5405c0c33bb1e52a544711e84bebe
ssdeep: 24576:Pe+V8PUd28d99ld6V0HyekrK0ndnd4hzq7r9PgXWn4PnxFVnrO:PmPUtdxtHRkBlduqBPEW4PjxO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6352202A6B04946D0DE91360554DF6DA61FDE80CE877C7217E12E3AB6222C43FED76E
sha3_384: ee6434014dfc3239c71efc7ba74ae8b8b69f0cd8170fa4582e1675839afcbab271a43be2622fda168576e06344314588
ep_bytes: 558bec6aff6868c22000680ca8200064
timestamp: 2016-11-24 02:41:37

Version Info:

Comments:
CompanyName:
FileDescription: I_go ്icroso聦t 基础类应用程序
FileVersion: 1, 0, 0,造1
InternalName: I_go
LegalCopyright: 版权所有 (C) 2000
LegalTrademarks:
OriginalFilename: 遉_go.EXE
PrivateBuild:
ProductName: I_go 应用程序
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.Agent.CBTY also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebBackDoor.Siggen2.1468
MicroWorld-eScanTrojan.Agent.CBTY
FireEyeGeneric.mg.1daf679d166fbbd2
CAT-QuickHealTrojan.Generic.ZZ4
ALYacTrojan.Agent.CBTY
CylanceUnsafe
VIPRETrojan.Agent.CBTY
SangforTrojan.Win32.Injector.1
K7AntiVirusTrojan ( 004ff9371 )
K7GWTrojan ( 004ff9371 )
Cybereasonmalicious.d166fb
BitDefenderThetaGen:NN.ZexaF.34806.dr3@a4G!Njqb
CyrenW32/Injector.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DIJX
APEXMalicious
ClamAVWin.Malware.Zusy-9793528-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.CBTY
NANO-AntivirusTrojan.Win32.DJCJ.elkrae
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ba7a0a
Ad-AwareTrojan.Agent.CBTY
EmsisoftTrojan.Agent.CBTY (B)
ComodoTrojWare.Win32.Kelihos.B@6okwz3
ZillyaBackdoor.Hlux.Win32.18692
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Kelihos
GDataTrojan.Agent.CBTY
JiangminTrojan.Generic.apjnu
AviraHEUR/AGEN.1230563
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3C54
ArcabitTrojan.Agent.CBTY
MicrosoftTrojan:Win32/Ditertag.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.R192579
McAfeeGenericRXAQ-UF!1DAF679D166F
VBA32OScope.Malware-Cryptor.Hlux
MalwarebytesZbot.Trojan.Stealer.DDS
RisingTrojan.Injector!1.A749 (CLASSIC)
YandexTrojan.GenAsa!FwSiFa3zDf8
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.DJCJ!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.CBTY?

Trojan.Agent.CBTY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment