Trojan

What is “Trojan.Win32.Agentb.jrhy”?

Malware Removal

The Trojan.Win32.Agentb.jrhy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.jrhy virus can do?

  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Agentb.jrhy?


File Info:

name: 89BBEAAC3EC1226F6071.mlw
path: /opt/CAPEv2/storage/binaries/dc51d06f9f7f64e4697fdd09377af9f28e5a51d4c13925a48d0b553b5547054c
crc32: E9B73696
md5: 89bbeaac3ec1226f607162b78a3dc80a
sha1: 7a3690e3976b42bde0b0b9d73e6cacaebd742ac1
sha256: dc51d06f9f7f64e4697fdd09377af9f28e5a51d4c13925a48d0b553b5547054c
sha512: 9b7d1151be3da812eff0ce3659f2234e392ec2ae5f03836ed4dbfbafeb7b04352f06256a2cb676236d4fab840aacbd97ff2aa87a86e7c537284ee24c0a28f5da
ssdeep: 12288:OFbTthAKzShSpMB7ViNG1WTqNt1yRkvLJXrY9XXXXXXhTmI8fhShPV7d1zembi:OpDPvgfKRSXrYt8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16EF4BF62F2D06C20D563B6FC0A2B96B5B0653CEAED71D98B08CE5CC61F69944FA75303
sha3_384: c0e8e49acee03c8d9b7438c5ae7ae7e450a40412c49d1a8856219213c617bf6a28b2eff79742cc49603a7a1cc91631f1
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Synaptics
FileDescription: Synaptics Pointing Device Driver
FileVersion: 1.0.0.4
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
Comments:
Translation: 0x041f 0x04e6

Trojan.Win32.Agentb.jrhy also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.89bbeaac3ec1226f
CAT-QuickHealSus.Nocivo.E0011
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
CyrenPP97M/Script.gen
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Trojan.Generic-9936029-0
KasperskyTrojan.Win32.Agentb.jrhy
NANO-AntivirusTrojan.Win32.Optix.fbquhj
CynetMalicious (score: 100)
RisingTrojan.Agentb!8.F8 (TFE:1:1nGTLUXLlCD)
SophosGeneric ML PUA (PUA)
ComodoHeur.Corrupt.PE@1z141z3
DrWebBackDoor.Optix.567
TrendMicroBackdoor.Win32.DARKCOMET.ENF
Trapminemalicious.high.ml.score
IkarusTrojan-PWS.Win32.QQPass
JiangminWin32/Synaptics.Gen
AviraTR/Dldr.Agent.SH
Antiy-AVLTrojan/Generic.ASMalwIH.13C
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmTrojan.Win32.Agentb.jrhy
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32Backdoor.Optix
MalwarebytesGeneric.Trojan.Injector.DDS
TrendMicro-HouseCallBackdoor.Win32.DARKCOMET.ENF
TencentTrojan.Win32.Agentb.yd
YandexTrojan.GenAsa!ETONJRQzPLk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Zorex-E [Wrm]
Cybereasonmalicious.3976b4
AvastWin32:Zorex-E [Wrm]

How to remove Trojan.Win32.Agentb.jrhy?

Trojan.Win32.Agentb.jrhy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment