Malware

Multi:Agent-EK [Trj] removal tips

Malware Removal

The Multi:Agent-EK [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Multi:Agent-EK [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Deletes executed files from disk

How to determine Multi:Agent-EK [Trj]?


File Info:

name: 4916454CD98D2506D927.mlw
path: /opt/CAPEv2/storage/binaries/f776a0fda7a563971f1b0dd6d478819d9b03371ece320407222de1757b1488ae
crc32: AD6F478A
md5: 4916454cd98d2506d92760e8e03a3f37
sha1: e396ded0f3e3b85473f2471c24c6bd6bd0c66f8b
sha256: f776a0fda7a563971f1b0dd6d478819d9b03371ece320407222de1757b1488ae
sha512: d55a45ea69028fe15e64a6db06cd6c0edcacfc76b63256a10e9b1a6c7b41cae56f2754d3e3b360878e8dc5a844c02f590f4127092e9dc0549cfc960a1be16dca
ssdeep: 393216:8xYQs+fgI0ktHVGnV8CmQPzqEbph1XgX1P8ijWXVH:8qQdfgv6HVmmWpDEEijWlH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6D6334337AD84A2E0BE5CF1493437E8FCB565256BC582BAE7487044BFE27C182267E5
sha3_384: da9b390b0b160b3020c40e8f24eb9e0e7f850b95ab077e205e843d648384d922d54e6b373893d7c11705fd43686a3d65
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Multi:Agent-EK [Trj] also known as:

LionicTrojan.Multi.Disco.i!c
DrWebPython.Stealer.491
MicroWorld-eScanTrojan.GenericKD.61230394
FireEyeGeneric.mg.4916454cd98d2506
ALYacTrojan.GenericKD.61230394
CylanceUnsafe
K7AntiVirusTrojan ( 00594f781 )
BitDefenderTrojan.GenericKD.61230394
K7GWTrojan ( 00594f781 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/S-f2662838!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Python/Spy.Agent.IE
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-PSW.Multi.Disco.gen
AlibabaTrojanPSW:Win32/Almi_Disco.b
Ad-AwareTrojan.GenericKD.61230394
SophosMal/Generic-R
TrendMicroTROJ_GEN.R002C0RH922
Trapminesuspicious.low.ml.score
AviraHEUR/AGEN.1251506
Antiy-AVLTrojan/Generic.ASMalwS.7780
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.61230394
GoogleDetected
Acronissuspicious
McAfeeArtemis!4916454CD98D
MAXmalware (ai score=85)
APEXMalicious
RisingStealer.Hazard!1.DF31 (CLASSIC)
IkarusTrojan-Spy.Python.HazardGrabber
FortinetPython/Agent.IE!tr.spy
AVGMulti:Agent-EK [Trj]
AvastMulti:Agent-EK [Trj]

How to remove Multi:Agent-EK [Trj]?

Multi:Agent-EK [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment