Malware

Win32/Agent_AGen.BLJ (file analysis)

Malware Removal

The Win32/Agent_AGen.BLJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.BLJ virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent_AGen.BLJ?


File Info:

name: 0268A680DD4D9F61B189.mlw
path: /opt/CAPEv2/storage/binaries/ad1b7e222a3c35485dadcbb6be4ecc070bd1e1feff7b09b827eea89fd781cd75
crc32: 3D753432
md5: 0268a680dd4d9f61b189cf08dd958058
sha1: c48af4aeaa7454023ead49d00e3b11f193ec3ab6
sha256: ad1b7e222a3c35485dadcbb6be4ecc070bd1e1feff7b09b827eea89fd781cd75
sha512: 2f4ff0c8efdcc90eb25cff734aa6c85b1775955c3b8fb3a38377d115ef8b319a728f83f35e35f3646a16607b49c0724c18771f35008b77156647f8cc23773b75
ssdeep: 3072:ZEMxVyGd9TiG0sjAon2fQZdN7XoALRwKqURBqdTvxE5smNK:Zou9TiG0KAo2fQPN7XoALR9qdltmNK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142643B113650C031E35627700D1AF7F15AA9BC394AA4A64FF7B87E3A5E31183AA3724F
sha3_384: ef7bb17b1da2c8a62dbdf05f56f703510a71aa58ee30bdc85b63da2d4bdb7f42783c3527d858598e3caef55326443060
ep_bytes: 00ff7604e8885cffff8b450883c42489
timestamp: 2014-07-02 12:38:36

Version Info:

0: [No Data]

Win32/Agent_AGen.BLJ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Urelas.4!c
MicroWorld-eScanGen:Variant.Zusy.452239
FireEyeGeneric.mg.0268a680dd4d9f61
SkyhighBehavesLike.Win32.Generic.fm
McAfeeGenericRXWJ-TY!0268A680DD4D
MalwarebytesUrelas.Trojan.Downloader.DDS
VIPREGen:Variant.Zusy.452239
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Zusy.452239
Cybereasonmalicious.eaa745
BitDefenderThetaGen:NN.ZexaF.36792.uCZ@au2lPTo
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.BLJ
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
KasperskyUDS:Trojan.Win32.GenericML.xnet
AlibabaTrojan:Win32/Urelas.71447e26
RisingTrojan.Urelas!1.BE13 (CLASSIC)
SophosMal/Generic-S
BaiduWin32.Trojan.Urelas.b
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.GenericML.Win32.8566
TrendMicroTROJ_GEN.R03BC0PK623
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.452239 (B)
IkarusTrojan.Win32.Urelas
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Urelas.DK.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Urelas.ab
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumTrojWare.Win32.Urelas.AB@56lb34
ArcabitTrojan.Zusy.D6E68F
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
GDataWin32.Trojan.PSE.122A5Z1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C5457170
Acronissuspicious
ALYacGen:Variant.Zusy.452239
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0PK623
TencentTrojan.Win32.Urelas.16000161
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Agent_AGen.BLJ?

Win32/Agent_AGen.BLJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment