Rootkit

Rootkit.Win32.Agent.elxy removal instruction

Malware Removal

The Rootkit.Win32.Agent.elxy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Agent.elxy virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Rootkit.Win32.Agent.elxy?


File Info:

name: C4DD4F0B9C6696A4C47C.mlw
path: /opt/CAPEv2/storage/binaries/93d7983152ae1654fc644fd634b7d04e6d82ad03b8fc16e8b1f51acdbec4ef6b
crc32: DCA6AD74
md5: c4dd4f0b9c6696a4c47ceae7d567542d
sha1: c89bbd0dcaaa278de9254ce28e80bd4867e8dbb0
sha256: 93d7983152ae1654fc644fd634b7d04e6d82ad03b8fc16e8b1f51acdbec4ef6b
sha512: ea2c561e9c4255ad8d93277b5ac1483a7ac6d57af14906ccbd80ff16e32c9b32990132d79a4b353346334bb9bd8dd1fb0e4e06c31f797ee25bf5d322ba0406a0
ssdeep: 24576:TyJOZiQxB5+Yzs4NVJa2r33E6CVL8V/y8k:TyJOZrAY3/JBENLx7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE35AE43F5A380F1DA1958711677A775AB329E170B128EC7E3D4FE291C361A1AF3312A
sha3_384: 44c0a484bfb87f5545a36dba408a88a5b55cff44cad2fc4c2a384b9decd69aa6b41d86e083a6f05feec0bc770e9cde4d
ep_bytes: 558bec6aff68302e4d00688cc5450064
timestamp: 2010-11-17 18:45:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Rootkit.Win32.Agent.elxy also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.c4dd4f0b9c6696a4
McAfeeGenericRXAE-DG!C4DD4F0B9C66
MalwarebytesPUP.Optional.ChinAd
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.dcaaa2
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyRootkit.Win32.Agent.elxy
NANO-AntivirusTrojan.Win32.TrjGen.dkgpmx
AvastWin32:Trojan-gen
ComodoWorm.Win32.Dropper.RA@1qraug
ZillyaTrojan.Genome.Win32.167703
McAfee-GW-EditionGenericRXAE-DG!C4DD4F0B9C66
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.10S0A6W
GoogleDetected
VBA32BScope.Trojan.Bitrep
CylanceUnsafe
IkarusTrojan.Win32.Genome
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34646.br2@aaIKU5cb
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Rootkit.Win32.Agent.elxy?

Rootkit.Win32.Agent.elxy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment