Malware

Win32/Agent.ABUD removal tips

Malware Removal

The Win32/Agent.ABUD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ABUD virus can do?

  • At least one process apparently crashed during execution
  • Unconventionial language used in binary resources: Turkish
  • Authenticode signature is invalid

How to determine Win32/Agent.ABUD?


File Info:

name: DF633DCD50381422468F.mlw
path: /opt/CAPEv2/storage/binaries/20286708d32f68a3fbec6576857a68a4fc6704d700a32d5d2992db49e777676b
crc32: 9BF19E82
md5: df633dcd50381422468fab937cd7cd4d
sha1: 016bd5833a35e4bfd0752c00da0fce693d37aea8
sha256: 20286708d32f68a3fbec6576857a68a4fc6704d700a32d5d2992db49e777676b
sha512: 9bf34d64e7d32e67d60c7aaf0bae6c9f6a5d536b53b398638df79af7256ae8acb2dd3d51b679ab92c9c65daa0454bfb00ecf77b3ed93b70ac744cd74a40b3bb5
ssdeep: 3072:5Hc9gCctxGv4QcU9KQ2BBA2waPxatmolMm:iuCctxGsWKQ2Bx5x6wm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C147D30E300C06AE8E142FEC6E68B76B6AC5F305F1440E7D7E1799A67356E6B83154B
sha3_384: 9ac8be59dd27c7cafa7335be6a74af2a1529eb244f976f2b1cbc0eb7a038f3a779918cce2e7436a621025bed20bc9e5d
ep_bytes: 558bec6aff68b07742006890a8400064
timestamp: 2011-08-09 17:50:27

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Win32/Agent.ABUD also known as:

BkavW32.FamVT.RenamerY.Trojan
LionicWorm.Win32.Juched.lyjw
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.44292
MicroWorld-eScanGen:Variant.Buzy.4160
FireEyeGeneric.mg.df633dcd50381422
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeW32/Autorun.worm.aacd
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 002a8f0e1 )
AlibabaMalware:Win32/km_2e7372.None
K7GWTrojan ( 001f4ea51 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34182.my1@auS@uzbG
CyrenW32/Agent.KI.gen!Eldorado
SymantecW32.Griptolo
ESET-NOD32a variant of Win32/Agent.ABUD
AvastWin32:Dropper-GHV [Drp]
KasperskyHEUR:Worm.Win32.Generic
BitDefenderGen:Variant.Buzy.4160
NANO-AntivirusTrojan.Win32.Juched.dfacwp
SUPERAntiSpywareTrojan.Agent/Gen-Ganel
TencentTrojan.Win32.FakeFolder.bba
SophosML/PE-A + W32/Autorun-BRF
ComodoWorm.Win32.Jushed.KA@4cysvx
BaiduWin32.Trojan.Agent.dc
McAfee-GW-EditionBehavesLike.Win32.Autorun.dz
EmsisoftGen:Variant.Buzy.4160 (B)
JiangminTrojan/Generic.acckw
eGambitUnsafe.AI_Score_99%
AviraTR/Spy.Agent.586689
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Occamy.sa
MicrosoftWorm:Win32/Ganelp.gen!A
ZoneAlarmHEUR:Worm.Win32.Generic
GDataGen:Variant.Buzy.4160
AhnLab-V3Trojan/Win32.Npkon.R18258
VBA32Trojan.Occamy
ALYacGen:Variant.Buzy.4160
MAXmalware (ai score=80)
MalwarebytesBackdoor.IRCBot
APEXMalicious
RisingTrojan.Fakefolder!1.6944 (CLOUD)
YandexTrojan.GenAsa!ceN4aAluftc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SRG!tr
AVGWin32:Dropper-GHV [Drp]
Cybereasonmalicious.d50381
PandaTrj/Genetic.gen

How to remove Win32/Agent.ABUD?

Win32/Agent.ABUD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment