Virus

Virus.Script.Agent.a removal tips

Malware Removal

The Virus.Script.Agent.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Script.Agent.a virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Suspicious wmic.exe use was detected

How to determine Virus.Script.Agent.a?


File Info:

name: 5BDED4903454B3EA0102.mlw
path: /opt/CAPEv2/storage/binaries/a7cfe836043696a54610f6619d26ea7219d836aba7590cda18e3e256412813f6
crc32: ABC1A962
md5: 5bded4903454b3ea0102cd85407dddd9
sha1: 61b00254b00647e60b0d73f78fa7af87d0c8f29c
sha256: a7cfe836043696a54610f6619d26ea7219d836aba7590cda18e3e256412813f6
sha512: 74e3c832aed3f9308f8fe46b4d40a464deda6c546b0c8d4814eb3f56d82aac2f660346516a2af5dc52db058785da8da52d2e92acf4a98e8d25dc5eafe0807603
ssdeep: 1536:37fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfrwZOqgOO:r7DhdC6kzWypvaQ0FxyNTBfropq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12F937C41F3E142F7EAF2053100A6722FD73663389764A8EBC74C2D529913AD5A63D3E9
sha3_384: b1a41b18237573c4a440fcdddba5cb41560d3e6f7255deab002662a07b02783f3f030c2472ba0df304b7c7366bfd6a79
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Virus.Script.Agent.a also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Encoder.trrL
MicroWorld-eScanGen:Heur.Bat.1
FireEyeGeneric.mg.5bded4903454b3ea
ALYacGen:Heur.Bat.1
MalwarebytesMalware.Heuristic.1008
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaVirus:Script/PowerShell.964a72b6
K7GWTrojan ( 005960f71 )
K7AntiVirusTrojan ( 005960f71 )
CyrenW32/Agent.EDI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32BAT/Agent.PLJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Script.Agent.a
BitDefenderGen:Heur.Bat.1
AvastOther:Malware-gen [Trj]
TencentScript.Virus.Agent.Jflw
TACHYONTrojan-Dropper/W32.Agent.93696.AO
EmsisoftGen:Heur.Bat.1 (B)
F-SecureMalware.BAT/Agent.wahsv
VIPREGen:Heur.Bat.1
TrendMicroTROJ_GEN.R002C0XGN23
McAfee-GW-EditionBehavesLike.Win32.RealProtect.nh
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.Bat.1
AviraBAT/Agent.wahsv
ArcabitTrojan.Bat.1
ZoneAlarmUDS:Virus.Script.Agent.a
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
McAfeeArtemis!5BDED4903454
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Chgt.AC
TrendMicro-HouseCallTROJ_GEN.R002C0XGN23
RisingTrojan.Generic@AI.99 (RDML:aSWUiOeaQp4GKDd/zhByYQ)
IkarusTrojan.PowerShell.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetBAT/Agent.PLJ!tr
AVGOther:Malware-gen [Trj]
Cybereasonmalicious.4b0064
DeepInstinctMALICIOUS

How to remove Virus.Script.Agent.a?

Virus.Script.Agent.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment