Trojan

Trojan.Agent.CPCE (B) removal guide

Malware Removal

The Trojan.Agent.CPCE (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CPCE (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan.Agent.CPCE (B)?


File Info:

name: EFE1239AFB0E32CBAA9F.mlw
path: /opt/CAPEv2/storage/binaries/e791fe054ae047edbab75e674f74d5db7862342d81ea98201ff1ce43df39106d
crc32: C9A51F72
md5: efe1239afb0e32cbaa9f5834651ee780
sha1: 7a7b94c32b72f57b3e237cdeec68a25503b131f9
sha256: e791fe054ae047edbab75e674f74d5db7862342d81ea98201ff1ce43df39106d
sha512: fa0aee692e3f67a5c3af7909e6950ad9fa8f0f977049f7009c686f2e579287cb48358d123aa5f5ac462af548e3833a4237a810f6f94fb224bf60e1535fb76e99
ssdeep: 12288:IRiLbacT34d8OYz2BtkpFbsKs0hIjMuZUNfxuWG++NhKS3iYTL76Inj:IUHard8lSnW0hjJK85Pie6Ij
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EE423041FA9AE27D47800381A3F964E4B837784745A99E25ADC1CEF4F2F97E4D8399C
sha3_384: 0060113885d883d16ec5304bb10c2e0a7cbd3dfe9726d8fdebe0cc1a35d8a05031d46c177ce75ed20405ad560e3fb4e5
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-10-24 11:18:43

Version Info:

Translation: 0x0000 0x04b0
Comments: QVBEVI
CompanyName: Q
FileDescription: QVBE
FileVersion: 6.1.1.1
InternalName: Ww00Ww.exe
LegalCopyright: Copyright © 3483
LegalTrademarks:
OriginalFilename: Ww00Ww.exe
ProductName: QVBEVI
ProductVersion: 6.1.1.1
Assembly Version: 4.5.7.5

Trojan.Agent.CPCE (B) also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CPCE
FireEyeGeneric.mg.efe1239afb0e32cb
McAfeePUP-GKL
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3576573
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055ca211 )
AlibabaTrojan:MSIL/Kryptik.7b1a0d9c
K7GWTrojan ( 0055ca211 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/S-df4dae5e!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.LFN
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.CPCE
NANO-AntivirusRiskware.Win32.WizzMonetize.euqfaz
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Generic.Aqgf
Ad-AwareTrojan.Agent.CPCE
SophosMal/Generic-S
ComodoTrojWare.MSIL.Kryptik.MGO@7dkl9e
DrWebAdware.WizzMonetize.1
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PJB21
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
EmsisoftTrojan.Agent.CPCE (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.CPCE
JiangminTrojan.Generic.hcjcf
eGambitUnsafe.AI_Score_100%
AviraADWARE/Wizrem.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.2270A5A
ArcabitTrojan.Agent.CPCE
SUPERAntiSpywareAdware.Tuto4PC/Variant
MicrosoftTrojan:Win32/Occamy.CE7
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/ADM01.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34062.Rm0@aKBgxEg
ALYacTrojan.Agent.CPCE
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesAdware.Tuto4PC.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PJB21
YandexTrojan.Agent!gJtBFDvnHZs
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.KZF!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.afb0e3
PandaTrj/GdSda.A

How to remove Trojan.Agent.CPCE (B)?

Trojan.Agent.CPCE (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment