Malware

About “Win32/Agent.UNT” infection

Malware Removal

The Win32/Agent.UNT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.UNT virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Agent.UNT?


File Info:

name: B49E79909E353A3FC2A2.mlw
path: /opt/CAPEv2/storage/binaries/db17577f2d4543f8606ba3488f4fc33e4effe541f12ce4fe2d8eec8497c9b97f
crc32: 5EB940CF
md5: b49e79909e353a3fc2a227b41aa07568
sha1: 7f445820dc0cfa2fb05cdfc1cc811fdcb3b4b006
sha256: db17577f2d4543f8606ba3488f4fc33e4effe541f12ce4fe2d8eec8497c9b97f
sha512: 42ace2b6913f788e0999c4f773aeaa5d856df5bd63c0236ad011d61967a896f64915d4414fc43eca2ed4d7377f6c9ee6c1cd322e0cdbaa6f386a6f131b184069
ssdeep: 1536:JWrpy1TuoXIbuVn2WX7wfumuU38u3yMXImbaLpY90+t32:MpyFuoXLn1wfuQ34Nx+t32
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15DB3F8D6BE8A9DA7FA21533D89F5D329133DFAC01B828B1B1D30983A47535E13EC5606
sha3_384: 6a2427df6b4632d8684fcca8ea6f08788c3b6d5bf2f492dca917c977d353bd4298dfd34f2c1ee9cf903a896f1ffdcfd2
ep_bytes: 83ec0cc705d853400001000000e8ae08
timestamp: 2022-02-05 19:31:16

Version Info:

0: [No Data]

Win32/Agent.UNT also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.12803
MalwarebytesTrojan.Agent
K7AntiVirusTrojan ( 002193031 )
BitDefenderGen:Variant.Fugrafa.12803
K7GWTrojan ( 002193031 )
Cybereasonmalicious.09e353
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.UNT
APEXMalicious
ClamAVWin.Malware.Agent-9870952-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Fugrafa.hzdbxs
MicroWorld-eScanGen:Variant.Fugrafa.12803
RisingTrojan.Agent!8.B1E (RDMK:cmRtazqLPR4ajBaRTuN8cSR5wB32)
EmsisoftGen:Variant.Fugrafa.12803 (B)
F-SecureHeuristic.HEUR/AGEN.1121983
DrWebTrojan.Click3.17654
ZillyaTrojan.Agent.Win32.1511430
FireEyeGeneric.mg.b49e79909e353a3f
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bedxs
AviraHEUR/AGEN.1121983
Antiy-AVLTrojan/Generic.ASMalwS.31A71DF
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Fugrafa.12803
AhnLab-V3Malware/Win32.Generic.C2287090
McAfeeGenericRXAA-AA!B49E79909E35
MAXmalware (ai score=84)
VBA32BScope.Trojan.Win64.Shelma
CylanceUnsafe
IkarusTrojan.Win32.Powerless
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Veil.C!tr
BitDefenderThetaGen:NN.ZexaF.34182.g8Y@au@oWrh
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Agent.UNT?

Win32/Agent.UNT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment