Malware

How to remove “Win32/Agent.ABMB”?

Malware Removal

The Win32/Agent.ABMB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ABMB virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

z.whorecord.xyz
api2.ttp1.cn
a.tomx.xyz

How to determine Win32/Agent.ABMB?


File Info:

crc32: 46FE5B37
md5: c21b5f9454fe2b79677a81a76b67be40
name: lock_all.exe
sha1: 74c9ed653cd1d0fdacf14ad7e51318c26b9fae50
sha256: d4bd4bdc76b2a01c7d7a37d518ab9274c1f5dd23741e25c3e180d11507dafc1c
sha512: 208a6baf306ddfcf21e07a68ae7ba33705e43dd13195bb127f2aa6554400ca3e0f4f99250e4ca7b0c01e686c06532a491ff364846d2a954554fc08c5ede0ed3a
ssdeep: 98304:7w0q7zteP+/CUtz0TNKiikR4p/ERw3YDS+AGbEdkZylfGI3C7o5vVXTd5zC3x:7w0q7zfmTNnKB5uvbHEliUHDU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Agent.ABMB also known as:

BkavHW32.Packed.
DrWebTrojan.DownLoader32.37835
MicroWorld-eScanTrojan.GenericKD.41985912
FireEyeGeneric.mg.c21b5f9454fe2b79
Qihoo-360Generic/HEUR/QVM19.1.FAAF.Malware.Gen
McAfeeArtemis!C21B5F9454FE
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.41985912
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_FRS.VSNW08K19
BitDefenderThetaGen:NN.ZexaF.34100.@FW@aGoKk5ii
CyrenW32/Trojan.RNQF-3138
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-7377321-0
GDataTrojan.GenericKD.41985912
AlibabaTrojan:Win32/Skeeyah.a641f98c
NANO-AntivirusTrojan.Win32.Dwn.gvzwop
RisingTrojan.Wacatac!8.10C01 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ZillyaTrojan.Agent.Win32.1281973
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
EmsisoftTrojan.GenericKD.41985912 (B)
SentinelOneDFI – Malicious PE
WebrootW32.Malware.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Skeeyah
ArcabitTrojan.Generic.D280A778
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3Malware/Win32.Generic.C3543429
ALYacTrojan.GenericKD.42620629
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Agent
ESET-NOD32Win32/Agent.ABMB
TrendMicro-HouseCallTROJ_FRS.VSNW08K19
IkarusTrojan.Win32.Skeeyah
eGambitUnsafe.AI_Score_50%
FortinetW32/FRS.VSNW08K19!tr
Ad-AwareTrojan.GenericKD.41985912
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.74681110.susgen

How to remove Win32/Agent.ABMB?

Win32/Agent.ABMB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment