Risk

What is “RiskTool.Win32.Agent.ajcn”?

Malware Removal

The RiskTool.Win32.Agent.ajcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.Agent.ajcn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine RiskTool.Win32.Agent.ajcn?


File Info:

name: E560EE5DE79D8699E1F4.mlw
path: /opt/CAPEv2/storage/binaries/a677aaf6d4e2065cf207d1f34c7dd32ffd5ff4fb6dae88f2431f32df0e3d2154
crc32: 3FD9AA91
md5: e560ee5de79d8699e1f4d6df45e59b35
sha1: 0e4c93f5578fcb04a56767a6430fa84eac2d5126
sha256: a677aaf6d4e2065cf207d1f34c7dd32ffd5ff4fb6dae88f2431f32df0e3d2154
sha512: dbb437fd70842373a63b38e5d491d0e8aae686878cfd325d1f7b8926b50bf5c35d4fcf194e77cffc5a2d6c4f2068e873447ffd665bc1130ec62a5554f7d58d6a
ssdeep: 12288:466mCYgoKy1abtNhAId6rvJnJmMdMvRBNOpMNfQPz1pm:466qvKyQ5N6LFkU6jkpMeRpm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBB42326473360C5D9DB4FFD0FD8A6BAA3BC1E8B12336A00BAC5B91B44B1361917564F
sha3_384: ee08b73e15fb5cac6c14227dc5fad9d8b53ed343897cb8f96168aa48f0f83ac062dcf061b3ad3ff93084f8dd7fd0474f
ep_bytes: 60be00b054008dbe0060ebff5783cdff
timestamp: 2008-01-27 14:33:23

Version Info:

Translation: 0x0804 0x04b0
Comments: Super Rabbit IE Expert
CompanyName: Super Rabbit Soft
LegalCopyright: Cai Xuan
LegalTrademarks: Super Rabbit
ProductName: Super Rabbit IE Expert
FileVersion: 8.50
ProductVersion: 8.50
InternalName: iepro
OriginalFilename: iepro.exe

RiskTool.Win32.Agent.ajcn also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Viking.l1lI
ClamAVWin.Trojan.Genlot-18
SkyhighBehavesLike.Win32.Sivis.hc
McAfeeArtemis!E560EE5DE79D
ZillyaTool.Agent.Win32.129560
SangforRiskware.Win32.Agent.Vnm7
AlibabaRiskWare:Win32/Generic.ec09673c
VirITTrojan.Win32.MulDrop.DKFG
APEXMalicious
Kasperskynot-a-virus:RiskTool.Win32.Agent.ajcn
NANO-AntivirusRiskware.Win32.Agent.eglhrw
AvastWin32:Malware-gen
RisingHacktool.Agent!8.335 (CLOUD)
DrWebTrojan.MulDrop.59624
Trapminesuspicious.low.ml.score
GoogleDetected
ZoneAlarmnot-a-virus:RiskTool.Win32.Agent.ajcn
Cylanceunsafe
YandexTrojan.GenAsa!DnEQg4InjoE
MaxSecureTrojan.Malware.197210165.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove RiskTool.Win32.Agent.ajcn?

RiskTool.Win32.Agent.ajcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment