Malware

What is “Win32/Agent_AGen.BUS”?

Malware Removal

The Win32/Agent_AGen.BUS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.BUS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.BUS?


File Info:

name: 24B69FAC38BF0B00143A.mlw
path: /opt/CAPEv2/storage/binaries/7753fe8dd14a9d676a0c30e72adeffdd2f8925bab08da9f1ccb594e434888478
crc32: 84596DCC
md5: 24b69fac38bf0b00143ab70713ea67f4
sha1: 85966320c26bbf0f926f62e7eb6c1223644ddeda
sha256: 7753fe8dd14a9d676a0c30e72adeffdd2f8925bab08da9f1ccb594e434888478
sha512: e70c114f7586800f2b8da80fd3a42e144297e83c5115cae500bd4536d70756312388ab3ecac92db139c8d63a70a01bbcd4a1a11cb5c33ebb1971368e728fb3c7
ssdeep: 192:6nzasS+7S+PA6xMUMOHzhQWt2/1LR8hiBorfLDQOXK0:ozaUu96xMUMOTW5NLuhBDLDQwB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183333C53A2DC6EFBC5D307707AF0422388B17458097E8A51A78C575FEEDAA8106393B2
sha3_384: 7e8413cf0550a67d538cb18f7aa334ca7727af5a725aa89a13e3aff545905bd3c59f67b91a3ef83078415f33eb4e2368
ep_bytes: f87304936eb8b760eb07263effcd9e2e
timestamp: 2023-07-28 10:00:00

Version Info:

FileDescription: Windows Initialization
OriginalFilename: wininit.exe
Translation: 0xffff 0x0000

Win32/Agent_AGen.BUS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
McAfeeArtemis!24B69FAC38BF
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.0c26bb
BitDefenderThetaGen:NN.ZexaF.36348.dq0@a8MScYi
CyrenW32/Backdoor.J.gen!Eldorado
SymantecPacked.Generic.114
ESET-NOD32a variant of Win32/Agent_AGen.BUS
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Convagent.gen
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:TrojanX-gen [Trj]
F-SecureTrojan.TR/Crypt.XPACK.Gen
McAfee-GW-EditionBehavesLike.Win32.BadFile.qz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.24b69fac38bf0b00
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.3RSSZU
AviraTR/Crypt.XPACK.Gen
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5464323
Cylanceunsafe
RisingPacker.Win32.Agent.g (CLASSIC)
YandexTrojan.Peed.Gen!Pac
IkarusTrojan-GameThief.Win32.Nilage
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.BELF!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Agent_AGen.BUS?

Win32/Agent_AGen.BUS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment