Trojan

Trojan-Banker.Win32.Agent.atgj removal instruction

Malware Removal

The Trojan-Banker.Win32.Agent.atgj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Agent.atgj virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan-Banker.Win32.Agent.atgj?


File Info:

name: DCC7CFAAC5AFFC93FF2E.mlw
path: /opt/CAPEv2/storage/binaries/e3f554add4cec0d7ecce4cc970b544b347e5d6ab7a7551643dcd7faee8eec92e
crc32: E1F51C08
md5: dcc7cfaac5affc93ff2e0c250535b227
sha1: 4adb1eae4df5d3b0323ed302b0004bd369112e33
sha256: e3f554add4cec0d7ecce4cc970b544b347e5d6ab7a7551643dcd7faee8eec92e
sha512: 7ae8924f926af23250e65766f694563a1159139ddb268c550daaeac3c895d1d8cbd5829300c896a8e2332b49f4883078a777463d4a34421e0ac13e34ef3f42f1
ssdeep: 393216:IhtjwVaDILvbv2iFzHKgBfZf42Ymh1oB2jtNzS8gpgjyP:IhFwVaDgUpmh1QkNzS8gp2yP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4F633271449564AD1F9CC3FD43BFE9173F6067B4AC274BE69C16EC6312D8A2A613C82
sha3_384: 794ae5209e2f7760663498a4cb36f3f5e0d718d6d98234ca3b31c95a35137df7c05dbea46ac58a388136a2dc3875cd19
ep_bytes: 68b7174f0de8634edd0033d885c803f8
timestamp: 2022-05-07 15:52:58

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan-Banker.Win32.Agent.atgj also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.dcc7cfaac5affc93
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan ( 0056e0311 )
K7GWTrojan ( 0056e0311 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/FlyStudio.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.Packed.AO potentially unwanted
APEXMalicious
KasperskyTrojan-Banker.Win32.Agent.atgj
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.PUPStudio.A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!DCC7CFAAC5AF
MalwarebytesPUP.Optional.ChinAd
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.Win32.Krypt
MaxSecureDropper.Dinwod.frindll
FortinetW32/GenKryptik.DLII!tr
BitDefenderThetaGen:NN.ZexaF.34666.@B0@aiZ4l5ab
Cybereasonmalicious.ac5aff

How to remove Trojan-Banker.Win32.Agent.atgj?

Trojan-Banker.Win32.Agent.atgj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment