Trojan

Trojan.BAT.Agentb (file analysis)

Malware Removal

The Trojan.BAT.Agentb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.BAT.Agentb virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan.BAT.Agentb?


File Info:

name: BF048CBC95E8B36480C0.mlw
path: /opt/CAPEv2/storage/binaries/8080f9f67855471e5131c3ac32d26b4ae62d44257c7e3042abf82741a779ba0e
crc32: 1B856D09
md5: bf048cbc95e8b36480c0d55e7bc8ac97
sha1: 1a0d17b0fc60f4ac639a7e9dcf30ba7f646572ed
sha256: 8080f9f67855471e5131c3ac32d26b4ae62d44257c7e3042abf82741a779ba0e
sha512: c7c80ef858c7e4fca58face1963704104df1a0464b502c47d9579228978b3274686c0c975e949e6102dfc57ba54e2bf82d75df6c3d7df777cb41144d6cb0a974
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4OE:fq6+ouCpk2mpcWJ0r+QNTBfzT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFA35A05B3E143FAC5E2043201BA503F9B76E52887646DE7C74C3C869653E998ABE3F5
sha3_384: edc7b28be49346055e169140f2c391e19f1fa07f6173466a33609ed0349442d6e3b4aa393c41b7ce2f0b34f4e89dc35b
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan.BAT.Agentb also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34305635
FireEyeGeneric.mg.bf048cbc95e8b364
SkyhighBehavesLike.Win32.Generic.nh
McAfeeArtemis!BF048CBC95E8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Niktol.3a4623b0
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.QBP
APEXMalicious
ClamAVWin.Malware.Agentb-10018199-0
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305635
AvastWin32:Evo-gen [Trj]
TencentTrojan.BAT.Agentb.hc
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.pmhod
VIPRETrojan.Generic.34305635
EmsisoftTrojan.Generic.34305635 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
GoogleDetected
AviraTR/Redcap.pmhod
VaristW32/Trojan.VFBA-8001
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20B7663
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataWin32.Trojan.PSE.1I3XF62
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R641831
VBA32Trojan.BAT.Agentb
ALYacTrojan.Generic.34305635
Cylanceunsafe
ZonerTrojan.Win32.85523
RisingTrojan.Starter/BAT!1.F40F (CLOUD)
YandexTrojan.Agent!I4Q/548sWx4
IkarusTrojan.Win32.Agent
MaxSecureTrojan.W32.BAT.Agentb.gen_S01
FortinetW32/Agent.EDI!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Niktol.RPY!MTB

How to remove Trojan.BAT.Agentb?

Trojan.BAT.Agentb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment