Rootkit

About “Rootkit.Win32.Agent.elxv” infection

Malware Removal

The Rootkit.Win32.Agent.elxv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Agent.elxv virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Rootkit.Win32.Agent.elxv?


File Info:

name: 17DF548C8AC1A1D5127B.mlw
path: /opt/CAPEv2/storage/binaries/aee2e831c2ee4e01db04abaf380dbf8d2de4988dab8412155b1835573de7a264
crc32: F6B2739A
md5: 17df548c8ac1a1d5127b84ec1ccf4c4c
sha1: 225335aecffc3d104a34ef640dde34953f5956b5
sha256: aee2e831c2ee4e01db04abaf380dbf8d2de4988dab8412155b1835573de7a264
sha512: 802cdec3025ca91aabf4433c4ebd47af5679b94c175059de913d1c281785e940bc1aa0ac1ea18e0d4ec0f9641608305636fb7e036f87be4dacb3a194540944c1
ssdeep: 1536:MlfimfA4Wz9b/4iLPOX3UUiFoRjaMLkXy5NtKbKY9GCtdqD2:iflfAsiLHEaML4yrtKOs/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182937D21F9C49072D85208B418AAD73086BEB8B90F1295C7FFD52E9D5F613D1A93437B
sha3_384: a0d933af6d55fd696ba13c21bb1634f8cefd223bc1ebf975fcca1d96db863ac173d1a2c78f5eb2066e38ed36491b0bd1
ep_bytes: e8692f0000e979feffff8bff558bec81
timestamp: 2012-07-12 02:56:49

Version Info:

0: [No Data]

Rootkit.Win32.Agent.elxv also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Daws.lIK3
MicroWorld-eScanTrojan.GenericKD.47479498
FireEyeTrojan.GenericKD.47479498
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGeneric Dropper.aoe
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.47479498
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056cd4c1 )
AlibabaTrojan:Win32/Systex.e62f9c7a
K7GWTrojan ( 0056cd4c1 )
Cybereasonmalicious.ecffc3
CyrenW32/Pleh.A.gen!Eldorado
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Mikey-9949492-0
KasperskyRootkit.Win32.Agent.elxv
BitDefenderTrojan.GenericKD.47479498
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Agent-AUSD [Rtk]
TencentTrojan.Win32.Nthook.a
TACHYONTrojan/W32.Agent.97536.L
EmsisoftTrojan.GenericKD.47479498 (B)
BaiduWin32.Rootkit.Agent.w
F-SecureTrojan.TR/Rogue.kdv.717131
DrWebTrojan.Click2.32800
ZillyaDropper.Daws.Win32.2427
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
SophosTroj/AutoG-M
IkarusTrojan.SuspectCRC
GDataWin32.Trojan.PSE1.YSVY3N
JiangminTrojan/Invader.gje
GoogleDetected
AviraTR/Rogue.kdv.717131
Antiy-AVLTrojan[Dropper]/Win32.Daws.aumx
XcitiumTrojWare.Win32.Clicker.naf@4qkqfk
ArcabitTrojan.Generic.D2D47ACA
ZoneAlarmRootkit.Win32.Agent.elxv
MicrosoftTrojanDropper:Win32/Systex!pz
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Daws.R34837
Acronissuspicious
ALYacTrojan.GenericKD.47479498
MAXmalware (ai score=81)
PandaTrj/CI.A
RisingTrojan.Agent!1.C16F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Dacic.1D3D!tr
AVGWin32:Agent-AUSD [Rtk]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Rootkit.Win32.Agent.elxv?

Rootkit.Win32.Agent.elxv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment