Trojan

What is “Trojan.Agent.EPBT”?

Malware Removal

The Trojan.Agent.EPBT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EPBT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.EPBT?


File Info:

name: 3BF90EE72CD1C4621276.mlw
path: /opt/CAPEv2/storage/binaries/a8f356faa1751a41e0d18391d831a5c2b61da396acb388139bd6a5e475550a71
crc32: 3262FA4C
md5: 3bf90ee72cd1c4621276bb3785b7cf9c
sha1: e937cf9ded89eea0ec40d2c5bcca9c460ba1bf81
sha256: a8f356faa1751a41e0d18391d831a5c2b61da396acb388139bd6a5e475550a71
sha512: bbc52274419ed61e3db7596d3155867478d10725affacfbb9e17b7c6403539d5de2d102aa9714cbe35053a870589947f3c26664bef1420b4ced7457819503f2c
ssdeep: 24:ZHGStUdaE0UrckeiR42OFfdo1WvvJZsOsyBKyoDa1KUJrTjn42vL61TRd0u/:ZvtcxveT2qf66BKjORJzn42D2dt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E81C88B46C16CB6E28C72B463E24A7BB177D8D80A339D0104C0A42F3CFE542E82DD44
sha3_384: bf72702afb26b8879f8c8fe9c4d7e90337493172ffed2fc7be2318c112490803f8ac58aa33ea516b43130e7c5a04d35e
ep_bytes: 680001000068102240006a00ff156830
timestamp: 2018-04-26 18:22:07

Version Info:

0: [No Data]

Trojan.Agent.EPBT also known as:

BkavW32.AIDetect.malware1
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/ATRAPS.ea0cd2bc
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.72cd1c
BitDefenderThetaGen:NN.ZexaF.34182.amX@aG1b2qp
VirITTrojan.Win32.ATRAPS.CET
CyrenW32/S-df653f98!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.IFKHYOK
TrendMicro-HouseCallTROJ_GEN.R002C0DB222
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.EPBT
NANO-AntivirusTrojan.Win32.Zusy.fazxdo
MicroWorld-eScanTrojan.Agent.EPBT
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Losf
EmsisoftTrojan.Agent.EPBT (B)
ComodoTrojWare.Win32.TrojanDownloader.Tiny.DF@7o68cl
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DB222
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ccqle
AviraTR/ATRAPS.Gen
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:WinNT/Rootkitdrv
ViRobotTrojan.Win32.Z.Zusy.4096.BKW
GDataTrojan.Agent.EPBT
AhnLab-V3Trojan/Win32.MDA.C1244824
VBA32Trojan.Fuerboos
MAXmalware (ai score=100)
APEXMalicious
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.GenAsa!i3knONEf/Lw
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.2DDC96!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.EPBT?

Trojan.Agent.EPBT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment