Malware

Win32/Agent_AGen.BYE malicious file

Malware Removal

The Win32/Agent_AGen.BYE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent_AGen.BYE virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent_AGen.BYE?


File Info:

name: CD18E330B9C5DA1421F5.mlw
path: /opt/CAPEv2/storage/binaries/de658f781249eae20b38c8e230ede01b592f3937dcd17c63569f8af32d4302a6
crc32: 7FEAD885
md5: cd18e330b9c5da1421f5c35316248e3b
sha1: bbf3dd321a6dafa8ba3756286b5b685b3621130e
sha256: de658f781249eae20b38c8e230ede01b592f3937dcd17c63569f8af32d4302a6
sha512: 039d5d395d0cbacbc8039289b384ac9095413b63feedf9de3f8cfec0c941356f05f4486e24eecdb95d6a8fb42480da7c5ca20e2798639ce5262392b09e3841b7
ssdeep: 6144:kX8DfgWWFcABwwvbVIn2f0/E7DNy4YGXO6mC/kWaZ:kX8DbgbVInOiek4YGXygsZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17634F1B1E350A073C45241301725DAAE7FAC6CB749B88C6BD7053B1E7ABE4E2B738516
sha3_384: a3aff7b03f85acdeb2136856cf2769008646084cfae057bba106c376045b85334983a42cf2680a5d7539018c3c72040c
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2010-09-25 10:50:55

Version Info:

CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 3, 0, 0, 0
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2009 QVOD
OriginalFilename: QvodInstall.exe
ProductName: QvodInstall Module
ProductVersion: 3, 0, 0, 0
Translation: 0x0409 0x04b0

Win32/Agent_AGen.BYE also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Otwycal.lmr7
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Win32.QVod.A
FireEyeGeneric.mg.cd18e330b9c5da14
Cylanceunsafe
VIPREGen:Win32.QVod.A
SangforSuspicious.Win32.Save.ins
K7AntiVirusBackdoor ( 00563cbc1 )
AlibabaExploit:Win32/ShellCode.59d4c208
K7GWBackdoor ( 00563cbc1 )
Cybereasonmalicious.0b9c5d
BitDefenderThetaGen:NN.ZexaF.36348.oK0@aG!YCihb
CyrenW32/S-81600b07!Eldorado
SymantecW32.Wapomi
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent_AGen.BYE
CynetMalicious (score: 100)
TrendMicro-HouseCallTROJ_GEN.R002C0DH323
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Win32.QVod.A
AvastWin32:AutoRun-BSV [Wrm]
TencentWin32.Trojan.Dropper.Jmnw
EmsisoftGen:Win32.QVod.A (B)
F-SecureBackdoor:W32/Agent.DQJS
BaiduWin32.Trojan.KillAV.c
TrendMicroTROJ_GEN.R002C0DH323
Trapminemalicious.high.ml.score
SophosMal/Mdrop-Y
SentinelOneStatic AI – Malicious PE
GDataGen:Win32.QVod.A
JiangminHeur:TrojanDownloader.Agent
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Exploit]/Win32.ShellCode
ArcabitGen:Win32.QVod.A
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
MicrosoftExploit:Win32/ShellCode.gen!B
GoogleDetected
AhnLab-V3Trojan/Win32.Qvod.R2044
Acronissuspicious
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
APEXMalicious
RisingTrojan.Wapomi!1.DCFE (CLASSIC)
IkarusExploit.Win32.RPC
MaxSecureVirus.W32.Qvod.A
FortinetW32/Agent_AGen.AXL!tr
AVGWin32:AutoRun-BSV [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent_AGen.BYE?

Win32/Agent_AGen.BYE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment