Trojan

Trojan.Win32.Agentb.kpvo (file analysis)

Malware Removal

The Trojan.Win32.Agentb.kpvo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.kpvo virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Trojan.Win32.Agentb.kpvo?


File Info:

name: ABA1242D4BD54CBE0AA4.mlw
path: /opt/CAPEv2/storage/binaries/441b93c15a2c58b8c19252ca5854cecff738dc870d3057cb9ab37fff616a933f
crc32: 47764BC3
md5: aba1242d4bd54cbe0aa4b1e88412e656
sha1: a18b85e5e783cb74096edae77f82b3d71d6f08e4
sha256: 441b93c15a2c58b8c19252ca5854cecff738dc870d3057cb9ab37fff616a933f
sha512: bf0f835c679d83f0dd9d7f64878f2354d1a861e691427931d9e921e27155fb01674339f989d4d72266d4be6a6dd6ead059991e27ec69710cf742158270831b79
ssdeep: 98304:aKiB2IWRSDptpn/NoY1MGLli61fj3XSmZaiZVlrBhHBP73TNb/:Nix71/uY1JX1LeivbhHZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E84623B722760045E4D5DC3A96337DE170FA07A6CB46B838A8AB6DC139265E1F323D53
sha3_384: 9c5e5d927cd341c5619c93740d60b287d46cddb6abc63c022b8a3b87402621705fe647c48ee0fd8cca16406cc3c50d05
ep_bytes: 686ce5b061e82394460003fae9934844
timestamp: 2021-09-06 06:42:12

Version Info:

FileVersion: 1.0.3.8
LegalCopyright: Copyright (C) 2021
ProductVersion: 1.0.3.8
Translation: 0x0804 0x04b0

Trojan.Win32.Agentb.kpvo also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agentb.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.37610000
FireEyeGeneric.mg.aba1242d4bd54cbe
McAfeeGenericRXRU-XE!ABA1242D4BD5
CylanceUnsafe
SangforTrojan.Win32.VMProtect.AR
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaPacked:Win32/VMProtect.5304f621
K7GWTrojan ( 7000001c1 )
K7AntiVirusTrojan ( 7000001c1 )
BitDefenderThetaGen:NN.ZexaF.34606.@F0@aiugJffj
CyrenW32/Agent.DPT.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.AR suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0PD722
AvastWin32:Malware-gen
ClamAVWin.Malware.Vmprotbad-9855134-0
KasperskyTrojan.Win32.Agentb.kpvo
BitDefenderTrojan.GenericKD.37610000
TencentWin32.Trojan.Agentb.Lpkz
Ad-AwareTrojan.GenericKD.37610000
SophosMal/Generic-S + Mal/VMProtBad-A
F-SecureHeuristic.HEUR/AGEN.1200244
TrendMicroTROJ_GEN.R002C0PD722
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.37610000 (B)
AviraHEUR/AGEN.1200244
KingsoftWin32.Troj.Agentb.kp.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.37610000
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4409700
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.GenericKD.37610000
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.VMP
APEXMalicious
RisingTrojan.Agentb!8.F8 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.846157.susgen
FortinetW32/Agent.ADER!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Agentb.kpvo?

Trojan.Win32.Agentb.kpvo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment