Trojan

Trojan.Agent.EXMP (B) (file analysis)

Malware Removal

The Trojan.Agent.EXMP (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EXMP (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.EXMP (B)?


File Info:

name: 09D0A233AD0705EBBC93.mlw
path: /opt/CAPEv2/storage/binaries/d0656a86463bf9530b8c39262faa0f850995e4c01b736eb97abf7f2c03a5213e
crc32: 7C1C0C56
md5: 09d0a233ad0705ebbc93cb3b914f93be
sha1: 9e5dff88e8b335f3300f89b18847811fac6cccc5
sha256: d0656a86463bf9530b8c39262faa0f850995e4c01b736eb97abf7f2c03a5213e
sha512: d78d58108f36e5e87015b57f41fd355cd61fafca6d942684f13352bcc7cfe10c38fa1d5f2d2c19a996e103296195ff22330cdfa629402d96dd36dd9c793bb746
ssdeep: 98304:3UJuxtxCaz2aTqPa7Q8SFpyVPKAxOyLIlsX7Ke:d2aqa7dOni
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA469E1272A4C175C1FA43B05A79CA0BE2397C754B3496DBF2D86A5E1E339C24B3A713
sha3_384: 47f9b7b2972e3b117f88ea2166f6ac92267e732907d06f8e9c5daf3de34b2c40794a1c64d908edf11ae3df03623855fc
ep_bytes: e80060000073ebebebeb73237dabebf3
timestamp: 2010-08-01 10:32:37

Version Info:

0: [No Data]

Trojan.Agent.EXMP (B) also known as:

BkavW32.OverlayND.PE
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.EXMP
FireEyeGeneric.mg.09d0a233ad0705eb
CAT-QuickHealWin32.Sivis.A4
McAfeePacked-SU!09D0A233AD07
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00517a0d1 )
K7GWTrojan ( 00517a0d1 )
Cybereasonmalicious.3ad070
CyrenW32/Zbot.GH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Ausiv.A
APEXMalicious
ClamAVWin.Trojan.Agent-6943819-1
KasperskyPacked.Win32.Krap.jc
BitDefenderTrojan.Agent.EXMP
NANO-AntivirusTrojan.Win32.Krap.espnuv
AvastWin32:Agent-BCFZ [Trj]
TencentTrojan.Win32.Kryptik.fwwy
Ad-AwareTrojan.Agent.EXMP
EmsisoftTrojan.Agent.EXMP (B)
ComodoVirus.Win32.VirLock.GA@7lv9go
DrWebTrojan.KillFiles.62112
ZillyaTrojan.Krap.Win32.8947
TrendMicroVirus.Win32.SIVIS.B
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/Generic-R
IkarusPacker.Win32.Krap
JiangminPacked.Krap.fyig
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Ausiv
ViRobotTrojan.Win32.Agent.Gen.C
ZoneAlarmPacked.Win32.Krap.jc
GDataWin32.Virus.Ausiv.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R236179
BitDefenderThetaAI:Packer.261445C01D
ALYacTrojan.Agent.EXMP
VBA32Trojan.KillFiles
MalwarebytesSivis.Virus.FileInfector.DDS
TrendMicro-HouseCallVirus.Win32.SIVIS.B
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgXBnJE79D+K8w)
YandexTrojan.GenAsa!8BX67dEhxck
SentinelOneStatic AI – Malicious PE
MaxSecurePacked.Krap.JC
FortinetW32/Ausiv.A
AVGWin32:Agent-BCFZ [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.EXMP (B)?

Trojan.Agent.EXMP (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment