Malware

Should I remove “Win32/Agent.AEYN”?

Malware Removal

The Win32/Agent.AEYN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.AEYN virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Agent.AEYN?


File Info:

name: A085C7AFA8AFB3ECD2D3.mlw
path: /opt/CAPEv2/storage/binaries/43453514c0f60aeac9c244fee7bc0021d224f03e02a2be8551ae0916f6fae9dc
crc32: 5E0144A1
md5: a085c7afa8afb3ecd2d30c94c229eaed
sha1: b92c0449439253e5d5361f87860fd7fafc5ec06c
sha256: 43453514c0f60aeac9c244fee7bc0021d224f03e02a2be8551ae0916f6fae9dc
sha512: 772f5addb61bdb8ab0be378950ad2181c9d813bc168d0fafed92bf2896b424e91a84b92307db70ba73d2746c0fcb1f17dc96332f523f375c6061ec649a2ed09a
ssdeep: 12288:dwAwMCDN3XO1/euguYfZFXr9KEvob1PrFGBGjxshS+Ud5xu4DPXJ:dwAwbN3XO1/euguY4b1PrgBGj5T
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13FE47C20B981C077E663113219EDE6E465ADB8310FA905C7B3881BBE9F3D3D15B3625B
sha3_384: 5f2cbeaa5622b2f1e6894579eb3aa80ac9d01d12023a1a4057f7a20f0df9c4e029eb8f059d664a175c9eee1f7deba74b
ep_bytes: e8dc110000e929feffff8b4df464890d
timestamp: 2022-12-07 08:26:22

Version Info:

FileVersion: 1.0.0.0
LegalCopyright: 2020-2022 All rights reserved
Translation: 0x0409 0x04b0

Win32/Agent.AEYN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.97721
ClamAVWin.Malware.Generickdz-9940561-0
FireEyeTrojan.GenericKDZ.97721
McAfeeGenericRXUX-MD!A085C7AFA8AF
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPRETrojan.GenericKDZ.97721
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059c4c61 )
AlibabaTrojan:Win32/Generic.69f3c1c1
K7GWTrojan ( 0059c4c61 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36250.Qy0@auYc4woi
VirITTrojan.Win32.PSWStealer.EPP
CyrenW32/Agent.FMC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.AEYN
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.97721
NANO-AntivirusTrojan.Win32.Mlw.jtysmz
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bdb59b
EmsisoftTrojan.GenericKDZ.97721 (B)
F-SecureTrojan.TR/Agent.nbyeh
ZillyaTrojan.Agent.Win32.3184368
TrendMicroTROJ_GEN.R002C0PCC23
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
SophosMal/Generic-S
GDataTrojan.GenericKDZ.97721
JiangminTrojan.Generic.hpbdu
AviraTR/Agent.nbyeh
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.Convagent
ArcabitTrojan.Generic.D17DB9
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Script/Phonzy.A!ml
GoogleDetected
AhnLab-V3Trojan/Win.OL.R512299
VBA32Trojan.Agent
ALYacTrojan.GenericKDZ.97721
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PCC23
RisingBackdoor.Convagent!8.123DC (TFE:5:2kIn4cHiTSI)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.ADKJ!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Agent.AEYN?

Win32/Agent.AEYN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment