Trojan

Trojan.Win32.Agentb.kjao removal

Malware Removal

The Trojan.Win32.Agentb.kjao is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.kjao virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agentb.kjao?


File Info:

crc32: B101E5C7
md5: e8973cd71c82dc96ea65bb6ef10dcbe7
name: E8973CD71C82DC96EA65BB6EF10DCBE7.mlw
sha1: 165f221030d0eae49d23617d9ab328caca0fd15a
sha256: 480d926b478a374b66c62345d5249fc431bb75ea09d0827378dd6050292fd102
sha512: 6e7d2552197a7beb4c71c3e5716e7a735f3b12115de6e2614212e1f80a92ff1fb0d2c76fbbb0d197eb816b4d1b78bd123a5b160b540b86dc03920a4d9c1863a3
ssdeep: 49152:2kn53QB2wW8zrKT3WKrScEEs4SOiEtY+OYIWKX5OdRpnYdP+Z9yToLhWOBY:N3820zrKTwcBHSatxCWXDpYdGCP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Corporis
ProductVersion: 2.8.5.7
FileDescription: Corporis Setup
Translation: 0x0000 0x04b0

Trojan.Win32.Agentb.kjao also known as:

K7AntiVirusTrojan ( 0056e5201 )
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1677
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.36319964
CylanceUnsafe
SangforTrojan.Win32.Wacatac.A
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Tnega.31bc0cdf
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.71c82d
CyrenW32/Agent.DBB.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Adware.Vosteran-9827148-0
KasperskyTrojan.Win32.Agentb.kjao
BitDefenderApplication.DealAlpha.2.Gen
NANO-AntivirusTrojan.Win32.Kryptik.ilxnge
MicroWorld-eScanApplication.DealAlpha.2.Gen
TencentWin32.Trojan.Agentb.Alsh
SophosDownload Assistant (PUA)
McAfee-GW-EditionBehavesLike.Win32.FileTour.vc
FireEyeApplication.DealAlpha.2.Gen
EmsisoftApplication.DealAlpha.2.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1138320
Antiy-AVLTrojan/Generic.ASMalwS.314AB3C
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.36319964
McAfeeArtemis!E8973CD71C82
MAXmalware (ai score=89)
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
MaxSecureTrojan.Malware.12142042.susgen
FortinetW32/Kryptik.GZFR!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.Win32.Agentb.kjao?

Trojan.Win32.Agentb.kjao removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment