Malware

Win32/Agent.TTB removal guide

Malware Removal

The Win32/Agent.TTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.TTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Agent.TTB?


File Info:

name: B3DF3D53D7DC96C85FA7.mlw
path: /opt/CAPEv2/storage/binaries/7ad692dc1d02ae2a6a5c6ddcfe3915024e5437644408a499ae04b18de3a9e256
crc32: 23C16FBF
md5: b3df3d53d7dc96c85fa72e4dc2d30725
sha1: bad32a820eb356e485c47e8ba0782286da08bf24
sha256: 7ad692dc1d02ae2a6a5c6ddcfe3915024e5437644408a499ae04b18de3a9e256
sha512: efdb8f3c569025b8afba236c109f37fd05067b2a25d44169499685ff3295c29e828121914e31234ffb0cce7a12a7537b502e940ae362f020721ce7c709ba0c5b
ssdeep: 49152:1zuVBBqXr9wZqNetFodX68X/91DA60PSe/JmYjl0r:BMBBI2qNC+dKC9Mxvp0r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1888533E09AB18B52FF7AC879E67876ABDB171028A547113EDD41C282DCB6FF014D9807
sha3_384: 80005daf477143eb7fa53ff09be5633cee88aea82d0fc64e2f53d235029ce87fed7bd56a84894038ed69a7e79f12914c
ep_bytes: 60be00c069008dbe0050d6ffc787e4d8
timestamp: 2018-11-16 04:35:10

Version Info:

0: [No Data]

Win32/Agent.TTB also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Razy.526391
FireEyeGeneric.mg.b3df3d53d7dc96c8
ALYacGen:Variant.Razy.526391
CylanceUnsafe
ZillyaTrojan.Tasker.Win32.716
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 004e6f751 )
AlibabaTrojan:Win32/Generic.6e9b6dbf
K7GWTrojan ( 004e6f751 )
Cybereasonmalicious.3d7dc9
BitDefenderThetaGen:NN.ZexaF.34084.SnGfamaf30ni
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.TTB
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.526391
NANO-AntivirusTrojan.Win32.Tasker.fkfmsa
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Pgmx
Ad-AwareGen:Variant.Razy.526391
EmsisoftGen:Variant.Razy.526391 (B)
ComodoMalware@#11tjoqdp5ddkp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
GDataGen:Variant.Razy.526391
JiangminTrojan.Tasker.lx
AviraHEUR/AGEN.1108826
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2985D87
ArcabitTrojan.Razy.D80837
MicrosoftTrojan:Win32/Occamy.C7A
CynetMalicious (score: 100)
AhnLab-V3Malware/RL.Generic.R244656
McAfeeArtemis!B3DF3D53D7DC
VBA32Trojan.Tasker
MalwarebytesMalware.Heuristic.1003
APEXMalicious
YandexTrojan.Tasker!TmjV5iCzF80
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.TJO!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Win32/Agent.TTB?

Win32/Agent.TTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment