Trojan

Trojan.Win32.Agentb.khzw removal guide

Malware Removal

The Trojan.Win32.Agentb.khzw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.khzw virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agentb.khzw?


File Info:

crc32: D62C555E
md5: 913594ad2abc233833e42bed557d4d18
name: 913594AD2ABC233833E42BED557D4D18.mlw
sha1: 0b05d289997ca8fc65fe60298bbdf836206a5016
sha256: a10a2f46fac1dfc76cca9686ad55d4b2cdba2e591c2251cb3e9f1d22b5745925
sha512: d3f8af5152dbc6489d60cf0e8d112607e5e37fa2165143d5b8e4622774053f2324cde53e1672d37267ae0145f189632d61a25447746d416c9975bdcbadfdf4aa
ssdeep: 1536:3EHjAreXU/iTC8m8plRTmKFImVAK27JCXowHzvIPxWtE8lEWl7:IkreXU/iTCp8ZCNkIPng
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: Copyright xa9 TekSuS
InternalName: JOURNALISTELEVERS
FileVersion: 3.01
CompanyName: TekSuS Silicon
LegalTrademarks: Copyright xa9 TekSuS
ProductName: Undebauchedness9
ProductVersion: 3.01
FileDescription: TekSuS Silicon
OriginalFilename: JOURNALISTELEVERS.exe

Trojan.Win32.Agentb.khzw also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36255650
Qihoo-360Win32/Trojan.Generic.HwMA4yoA
ALYacTrojan.GenericKD.36255650
MalwarebytesTrojan.MalPack.VB
SangforMalware
K7AntiVirusTrojan ( 00576e6b1 )
BitDefenderTrojan.GenericKD.36255650
K7GWTrojan ( 00576e6b1 )
ArcabitTrojan.Generic.D22937A2
CyrenW32/VBKrypt.AQC.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agentb.khzw
AlibabaTrojan:Win32/Injector.806c6b8d
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.36255650
SophosTroj/VB-KWC
F-SecureTrojan.TR/Dropper.VB.tkqnf
TrendMicroTROJ_FRS.0NA103AS21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36255650
EmsisoftTrojan.GenericKD.36255650 (B)
AviraTR/Dropper.VB.tkqnf
MAXmalware (ai score=89)
KingsoftWin32.Troj.Agentb.kh.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Agentb.khzw
GDataTrojan.GenericKD.36255650
CynetMalicious (score: 85)
McAfeePWS-FCVW!913594AD2ABC
CylanceUnsafe
ESET-NOD32a variant of Win32/Injector.EOIE
TrendMicro-HouseCallTROJ_FRS.0NA103AS21
RisingTrojan.Injector!8.C4 (TFE:5:5gvTcbu1le)
IkarusTrojan.VB.Crypt
BitDefenderThetaGen:NN.ZevbaF.34780.im1@aK0SR5bb
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Trojan.Win32.Agentb.khzw?

Trojan.Win32.Agentb.khzw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment