Malware

Win32/Agent.ABDL removal guide

Malware Removal

The Win32/Agent.ABDL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ABDL virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Leivion malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Agent.ABDL?


File Info:

name: 1894CFC4F407476A592B.mlw
path: /opt/CAPEv2/storage/binaries/eae3acfde062b629b76df642ca080140fec2c36c6db7602099d9adf0ea5728ff
crc32: 4DE6F907
md5: 1894cfc4f407476a592b561a9267fd39
sha1: 2edba3e587270bac4115b82127f775847353af0b
sha256: eae3acfde062b629b76df642ca080140fec2c36c6db7602099d9adf0ea5728ff
sha512: a37c0368b06d4437f69a65647aae367d23a5d828a9f842a30cfc7525dc2ef31a73156431abcd435c542b203e882df18e3dccee9dc69b6ac06e08bdc56f2464e0
ssdeep: 24576:zcqrteI/VFoBx/K/mZl7ousZT2snq3rlnI3pHJ8K1StE10cqRpF5Yg9vIeXPNKvC:Vts8L26uuT8vEUQeQHA8WxW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6D508C0F9DB40F6E1078E7288E2523FAB30564893B8CAD7DF641A59EC1B6E1187B715
sha3_384: 5890cc5965b30c5531c6c688a775f35b702e4d0cdba9d72d5c45668a645342c17b861815a3718dfdac7b404a21352b50
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Win32/Agent.ABDL also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
MicroWorld-eScanGen:Variant.Trojan.Liev.9
SkyhighBehavesLike.Win32.TrojanVeil.vh
ALYacGen:Variant.Trojan.Liev.9
Cylanceunsafe
VIPREGen:Variant.Trojan.Liev.9
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050f7371 )
K7GWTrojan ( 0050f7371 )
Cybereasonmalicious.4f4074
ArcabitTrojan.Trojan.Liev.9
BitDefenderThetaGen:NN.ZexaF.36802.VsW@aSkXbin
SymantecHacktool.Veil!g3
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ABDL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Liev-9638375-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Trojan.Liev.9
NANO-AntivirusTrojan.Win32.Mlw.epmqcf
AvastWin32:Evo-gen [Trj]
RisingTrojan.Agent!1.E34D (CLASSIC)
EmsisoftGen:Variant.Trojan.Liev.9 (B)
F-SecureHeuristic.HEUR/AGEN.1314221
DrWebBackDoor.Siggen2.2205
FireEyeGeneric.mg.1894cfc4f407476a
SophosATK/Veil-AZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bbhak
AviraHEUR/AGEN.1314221
MicrosoftTrojan:Win32/Leivion.S
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.M0TZW0
VaristW32/S-a0eadfad!Eldorado
AhnLab-V3Malware/Win32.RL_Generic.R266227
McAfeeTrojan-Veil-FLRK!1894CFC4F407
MAXmalware (ai score=83)
VBA32BScope.Trojan.Leivion
MalwarebytesGeneric.Malware.AI.DDS
TencentMalware.Win32.Gencirc.10b1bff2
IkarusTrojan.Win32.Leivion
FortinetW32/Agent.YXS!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Agent.493d4bb4

How to remove Win32/Agent.ABDL?

Win32/Agent.ABDL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment