Malware

Win32/Agent.AAKP information

Malware Removal

The Win32/Agent.AAKP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.AAKP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics

How to determine Win32/Agent.AAKP?


File Info:

name: 7313BD35CD5D12F8BF9A.mlw
path: /opt/CAPEv2/storage/binaries/9a8d73cb7069832b9523c55224ae4153ea529ecc50392fef59da5b5d1db1c740
crc32: 54EF4689
md5: 7313bd35cd5d12f8bf9acf18dfb50717
sha1: 203fbc7ab159fe13ea247724e287a18ed5da4b90
sha256: 9a8d73cb7069832b9523c55224ae4153ea529ecc50392fef59da5b5d1db1c740
sha512: 2ac8b462407bbae521b7277f977f530a75da60aeea70e4ee51038d0ea1902dcf7ee62d49269d1b3ef31168c17d93b3974efbd5ed44387d4a73cd6d1167faf02f
ssdeep: 12288:5MO5rrcCJzY/A+FDk8id41X0yWj3Kfsr7LNAQPWdu1LEJyZ:5MArrcClY/RDk8P0yW73r1RPWd8h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3C4238053DDFE97F0289830AB9B97A5533EF12DA4F649F1318D6AA79820E53481F335
sha3_384: 77adfbf5d28e377c5021cd88a984f2e4531a852e3ea1ada4c2880aa77de547c74f7de39596cc6066cce2c78e189dc1de
ep_bytes: eb056994ad131b50eb010be817000000
timestamp: 2016-01-25 12:25:18

Version Info:

Comments:
CompanyName: PortableApps.com
FileDescription: DB Browser for SQLite Portable (PortableApps.com Launcher)
FileVersion:
InternalName: PortableApps.com Launcher
LegalCopyright: PortableApps.com
LegalTrademarks:
OriginalFilename: SQLiteDatabaseBrowserPortable.exe
ProductName: DB Browser for SQLite Portable
ProductVersion: 2.2.0.0
Translation: 0x0000 0x04b0
SpecialBuild:
BuildID:

Win32/Agent.AAKP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4357104
ALYacTrojan.GenericKD.4357104
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.103647
SangforTrojan.Win32.Downeks.uppyg
K7AntiVirusTrojan ( 005022d51 )
AlibabaTrojanDropper:Win32/FAKEDOBE.2adc8e0a
K7GWTrojan ( 005022d51 )
Cybereasonmalicious.5cd5d1
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.AAKP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Downeks-6394305-0
KasperskyHEUR:Trojan-Dropper.Win32.Sysn.gen
BitDefenderTrojan.GenericKD.4357104
NANO-AntivirusTrojan.Win32.Agent.ekhhtk
TencentWin32.Trojan.Generic.Aedv
Ad-AwareTrojan.GenericKD.4357104
EmsisoftTrojan.GenericKD.4357104 (B)
ComodoMalware@#3m0105s347d44
DrWebTrojan.DownLoader23.45316
VIPRETrojan.GenericKD.4357104
TrendMicroBKDR_FAKEDOBE.JM
McAfee-GW-EditionGeneric trojan.qh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7313bd35cd5d12f8
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.4357104
JiangminTrojanDropper.Sysn.gmb
WebrootW32.Malware.Gen
GoogleDetected
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2D10
KingsoftWin32.Hack.Agent.do.(kcloud)
ArcabitTrojan.Generic.D427BF0
ZoneAlarmHEUR:Trojan-Dropper.Win32.Sysn.gen
MicrosoftTrojan:Win32/Occamy.C9A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C5216612
Acronissuspicious
McAfeeGeneric .qh
VBA32BScope.Trojan.Packed
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallBKDR_FAKEDOBE.JM
RisingTrojan.Generic@AI.100 (RDML:4RYH9s7oUFnlSKgmuwEk6A)
IkarusTrojan.Win32.Agent
BitDefenderThetaGen:NN.ZexaF.34592.Jq3@aOkLJ4fi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent.AAKP?

Win32/Agent.AAKP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment