Trojan

Should I remove “Trojan.Win32.Agentb.btmh”?

Malware Removal

The Trojan.Win32.Agentb.btmh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.btmh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Agentb.btmh?


File Info:

name: 165D92641E1D83F46F96.mlw
path: /opt/CAPEv2/storage/binaries/0defbf08d911e2aee1ed01db899b6666bb3a8304afa33f27623c6a776c631ff0
crc32: 9E8D81A0
md5: 165d92641e1d83f46f96ae7d3cabb343
sha1: bcd49e6a04e93c1f62a750fcaceb4d622d564206
sha256: 0defbf08d911e2aee1ed01db899b6666bb3a8304afa33f27623c6a776c631ff0
sha512: a01f0fc115e615bc3695a56382bc40a1923c49be2bc1a7353f5d262728d91df09d92989b2a2a8e0b004e9a1348081427f4b81d961f611eeff2d9020ed9821b57
ssdeep: 3072:/VMKsWKxlGxE07ABigCFHdLYyBvzyBHNGqXgvnHZyzi0zslLFh/FzKsRSP:93sWKxQ52CFHdLYKvzyZNGX/IupJ2sQP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12914436BF121C054E59240B8742CEA8AF55C7E7305446972FB81BB5939B27EFA0F6B03
sha3_384: 3f35fff7f56986b1de095f8bfcf38054c94c09bc353334814d45b4db89aa87b86eeb7063f9cdb52404894aab830ab3b1
ep_bytes: 6868784000e8f0ffffff000000000000
timestamp: 2014-03-20 10:41:32

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: DOCUMENT
OriginalFilename: DOCUMENT.exe

Trojan.Win32.Agentb.btmh also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agentb.tnql
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.VB.Agent.ABT
FireEyeGeneric.mg.165d92641e1d83f4
CAT-QuickHealWorm.Copali.OD3
ALYacBackdoor.VB.Agent.ABT
CylanceUnsafe
VIPRETrojan.Win32.Swisyn.dfkc (fs)
K7AntiVirusP2PWorm ( 00486ea71 )
BitDefenderBackdoor.VB.Agent.ABT
K7GWP2PWorm ( 00486ea71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.D7ADE4761F
CyrenW32/A-0d9bc26b!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/VB.OLE
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Cerber-7134131-0
KasperskyTrojan.Win32.Agentb.btmh
NANO-AntivirusTrojan.Win32.TrjGen.deyzgg
ViRobotTrojan.Win32.Zbot.184320.D
RisingWorm.Copali!1.A2C3 (CLASSIC)
Ad-AwareBackdoor.VB.Agent.ABT
SophosMal/Generic-R + Troj/VB-HTM
BaiduWin32.Worm.VB.bf
DrWebTrojan.Siggen6.19362
ZillyaTrojan.Swisyn.Win32.32299
TrendMicroWORM_COPALI_EJ200083.UVPM
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
EmsisoftBackdoor.VB.Agent.ABT (B)
JiangminTrojan/Swisyn.wsw
AviraTR/Beebone.rhwnabs
Antiy-AVLTrojan/Generic.ASMalwS.93BFFC
MicrosoftWorm:Win32/Copali.B
GridinsoftRansom.Win32.Zbot.sa
SUPERAntiSpywareTrojan.Agent/Gen-Symmi
GDataBackdoor.VB.Agent.ABT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R106377
McAfeeW32/Worm-GAM!165D92641E1D
MAXmalware (ai score=80)
VBA32Trojan.Agentb
MalwarebytesTrojan.Agent
PandaGeneric Malware
TrendMicro-HouseCallWORM_COPALI_EJ200083.UVPM
TencentMalware.Win32.Gencirc.10b0cd1f
YandexTrojan.GenAsa!UB1ZEjQvu58
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.1EEAF!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.41e1d8
AvastWin32:Vitro [Inf]

How to remove Trojan.Win32.Agentb.btmh?

Trojan.Win32.Agentb.btmh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment