Trojan

Trojan:Win32/Agent.PA!MTB malicious file

Malware Removal

The Trojan:Win32/Agent.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Agent.PA!MTB virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

Related domains:

lovecatalog.comlu.com
yourssagregator.comlu.com
www.000webhost.com
ocsp.comodoca.com
crl.usertrust.com
ocsp.usertrust.com
allnewsmedia.webatu.com

How to determine Trojan:Win32/Agent.PA!MTB?


File Info:

crc32: 95CEFB78
md5: 98fa147eaa7c0fb8d8d60102e85baec7
name: 98FA147EAA7C0FB8D8D60102E85BAEC7.mlw
sha1: 6f49af1550ca8880fd1f13c84a0b3765bb7b2c26
sha256: c92f2612dac68a95141a0a2c6d19d18b849d4a8d31e2332a3ea99e4b9d893a4f
sha512: 43b0af2066f0a4d7055de9e94d4fd617bc3ad2e66578a0f40d12bea90bf8fb5de37da965bd0938247855da7695bfeae28e746505125e2b437b432d2243a480ba
ssdeep: 1536:LDlUTJ98nIC7bEPAS/jNKP6XGOlcVIN8nm/JKIyjUlww:aTjI7bEPAEQyr6VfnWoIMUlx
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Agent.PA!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Firefox.467
ClamAVWin.Dropper.Ramnit-9886751-0
CAT-QuickHealW32.Virut.Cur1
ALYacGen:Variant.Doina.8331
MalwarebytesPolyRansom.Virus.FileInfector.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Foreign.713a803d
K7GWTrojan ( 000206701 )
K7AntiVirusTrojan ( 000206701 )
BaiduWin32.Virus.Virut.gen
CyrenW32/Ransom.AR.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Virut.NBP
APEXMalicious
AvastWin32:Karagany-OV [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Foreign.gen
BitDefenderGen:Variant.Doina.8331
NANO-AntivirusTrojan.Win32.RiskGen.csficz
ViRobotTrojan.Win32.A.Foreign.42496.C
MicroWorld-eScanGen:Variant.Doina.8331
TencentTrojan.Win32.Foreign.ya
Ad-AwareGen:Variant.Doina.8331
SophosML/PE-A + Mal/Agent-ATP
ComodoTrojWare.Win32.Beaugrit.F@7hes6g
BitDefenderThetaAI:Packer.F9EE9FF21F
VIPREVirus.Win32.Virut.ce.6 (v)
TrendMicroTSPY_FORCOM.SM
McAfee-GW-EditionBehavesLike.Win32.HLLP.kh
FireEyeGeneric.mg.98fa147eaa7c0fb8
EmsisoftGen:Variant.Doina.8331 (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.bv
AviraHEUR/Patched.Ren
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.25F3A1
KingsoftHeur.SSC.2695679.1216.(kcloud)
MicrosoftTrojan:Win32/Agent.PA!MTB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Foreign.gen
GDataGen:Variant.Doina.8331
AhnLab-V3Trojan/Win32.Foreign.R89440
Acronissuspicious
McAfeeGenericRXED-MI!98FA147EAA7C
MAXmalware (ai score=81)
VBA32BScope.TrojanPSW.Firefox
PandaW32/Sality.AO
TrendMicro-HouseCallTSPY_FORCOM.SM
RisingTrojan.Generic@ML.100 (RDML:wnipMfv6A+taiUOdpUPOZw)
YandexTrojan.GenAsa!fRYR5MhW5Uk
IkarusTrojan-Ransom.Foreign
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NNA!tr
AVGWin32:Karagany-OV [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Agent.PA!MTB?

Trojan:Win32/Agent.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment