Trojan

Trojan.Win64.Agentb.afc malicious file

Malware Removal

The Trojan.Win64.Agentb.afc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Agentb.afc virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

superstationcity.com
prophefliloc.tumblr.com
google.vrthcobj.com
most-fast-link-download.com
ocsp.comodoca.com
ocsp.usertrust.com
crl.usertrust.com
ip-api.com
a.upstloans.net
apps.identrust.com

How to determine Trojan.Win64.Agentb.afc?


File Info:

crc32: 9C6DAE74
md5: 20eb6b8655de71aad0ba6e71a045b1f6
name: 20EB6B8655DE71AAD0BA6E71A045B1F6.mlw
sha1: 1770246098ea07e2024dd31de0fba54916d7236b
sha256: 685933af075d310ddb454b399641cfdbf801441e5360df0e71204d63d2afc757
sha512: bb6a8f071ca9d77ab6c10f90b3ba1ad1e86c7b326fa7731c13fde95554bba97cf374878a64a7ad4fec0aee3301751ab32d280a8c440aa78319fc89f5391f2259
ssdeep: 49152:pAI+mPQQSU9afXEDN50Qx8lMmD4gGovWhJLEx2BwDPw1V46hi5SC0DNdSM2SwMpt:pAI+M4UsuNxyvGoOnEx2BoQVlhi5S9OG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: GameBox INC
FileDescription: GameBox 5 Installation
FileVersion: 5
Comments:
CompanyName: GameBox INC
Translation: 0x0409 0x04e4

Trojan.Win64.Agentb.afc also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005801f11 )
DrWebTrojan.DownLoader40.50532
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.37325827
CylanceUnsafe
K7GWTrojan ( 005801f11 )
CyrenW64/Upatre.MP.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
AvastWin64:Trojan-gen
KasperskyTrojan.Win64.Agentb.afc
BitDefenderTrojan.GenericKDZ.76738
NANO-AntivirusTrojan.Win32.Inject4.ixgvgd
MicroWorld-eScanTrojan.GenericKDZ.76738
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilF.34058.lu0@aua40Ym
FireEyeTrojan.GenericKDZ.76738
EmsisoftTrojan.GenericKDZ.76738 (B)
AviraTR/Crypt.Agent.htcdi
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.340C0ED
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Generic.D12BC2
GDataTrojan.GenericKD.37325827
MAXmalware (ai score=84)
VBA32Trojan.Inject
IkarusTrojan.Win32.Meredrop
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
AVGWin64:Trojan-gen
Qihoo-360HEUR/QVM05.1.0E1F.Malware.Gen

How to remove Trojan.Win64.Agentb.afc?

Trojan.Win64.Agentb.afc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment