Trojan

What is “Trojan.Agent.CGDB”?

Malware Removal

The Trojan.Agent.CGDB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CGDB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.CGDB?


File Info:

crc32: 1724F0BA
md5: 131d1e05649216da7d3aac86cb0cb1ed
name: upload_file
sha1: 3fccbf64126d9c4e7880e868722310d4aded9798
sha256: 0d56de71fd541b777edbd246e23360cbcab6bddd2ed18ac078fcf29533738a93
sha512: 684f670f7b052e32b499164376fb517c665b58d4380ec5df600a1a43c3a904ba07a152f0f1b0705751e3951b2bc0affdb8590663116c3b43853ab7f5d3e039e9
ssdeep: 12288:2A9qvbK+YMWshiJurvJXD5ygDziPlHbHL+y6:QvW+6ADJTgyiPlHbr+y6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Euronics
InternalName: Presnings
FileVersion: 9.05.0006
CompanyName: Euronics
LegalTrademarks: Euronics
Comments: Euronics
ProductName: Euronics
ProductVersion: 9.05.0006
FileDescription: Euronics
OriginalFilename: Presnings.exe

Trojan.Agent.CGDB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CGDB
CAT-QuickHealRansom.Zerber.V3
McAfeePWSZbot-FAYC!131D1E056492
VIPRELooksLike.Win32.Beebone.a (v)
SangforMalware
K7AntiVirusTrojan ( 0050bb771 )
K7GWTrojan ( 0050bb771 )
Cybereasonmalicious.564921
ArcabitTrojan.Agent.CGDB
InvinceaML/PE-A + Mal/FareitVB-M
CyrenW32/S-27a9827b!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.VBKryjetor.alcp
BitDefenderTrojan.Agent.CGDB
NANO-AntivirusTrojan.Win32.VBKryjetor.enwiee
AvastWin32:Malware-gen
RisingRansom.Cerber!8.3058 (TFE:3:Cwe6T9mReeS)
Ad-AwareTrojan.Agent.CGDB
EmsisoftTrojan.Agent.CGDB (B)
F-SecureHeuristic.HEUR/AGEN.1112811
DrWebTrojan.Encoder.10731
McAfee-GW-EditionBehavesLike.Win32.Fareit.gm
SophosMal/FareitVB-M
SentinelOneDFI – Malicious PE
AviraHEUR/AGEN.1112811
Antiy-AVLTrojan/Win32.TSGeneric
AegisLabTrojan.Win32.VBKryjetor.4!c
ZoneAlarmTrojan.Win32.VBKryjetor.alcp
GDataTrojan.Agent.CGDB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
Acronissuspicious
BitDefenderThetaAI:Packer.230EAEDE21
ALYacTrojan.Agent.CGDB
MAXmalware (ai score=89)
CylanceUnsafe
ESET-NOD32a variant of Win32/Injector.DNZQ
TrendMicro-HouseCallTSPY_HPLOKI.SMDS
TencentMalware.Win32.Gencirc.10bb9d18
YandexTrojan.VBKryjetor!
IkarusTrojan.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CJGS!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.CGDB?

Trojan.Agent.CGDB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment