Trojan

How to remove “Trojan.Agent.24842”?

Malware Removal

The Trojan.Agent.24842 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.24842 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Attempts to modify Internet Explorer’s start page
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Agent.24842?


File Info:

name: D54F1CEB3D200D701C80.mlw
path: /opt/CAPEv2/storage/binaries/b8c6dfd211bbb0c38c7aacf079a395281bc0f602bcea3b05e328d527e8e7e49f
crc32: 83E94980
md5: d54f1ceb3d200d701c8073ca163a6992
sha1: 0f9ee798d5091fe91b25cee8aa54758fcf18643d
sha256: b8c6dfd211bbb0c38c7aacf079a395281bc0f602bcea3b05e328d527e8e7e49f
sha512: cef160b91d2547ec9beaea21fb8b6703822850b7db6fd3769122c8d65e84937a1288391c48f9ea1230daf2dfe6ec3478f822f4bf417d697e89c31062cf56d6dc
ssdeep: 192:i4YucS/W/7sw44B7tzthpoUO29vttXVFh315lOeVrJ9CkLGW5g4:i41TisM7tJol29zjBfpP9Xfa4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155629DF7F7702245F4FF46344AB76B551D28BC314134EA0E15E03EEE2EA13A08A02AB4
sha3_384: 037f88083e354e2a572e54036b6ad31dbdca3d6c0b3bdfa61f7d2e16c4a317830fd2af5b000f9f4e73e0a5234882ac64
ep_bytes: 60be00a040008dbe0070ffff5783cdff
timestamp: 2004-03-27 10:37:04

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Soeperman Enterprises Ltd.
FileDescription: Look2Me parasite remover
LegalCopyright: Soeperman Enterprises Ltd.
ProductName: Kill2Me
FileVersion: 1.04.0001
ProductVersion: 1.04.0001
InternalName: Kill2Me
OriginalFilename: Kill2Me.exe

Trojan.Agent.24842 also known as:

MicroWorld-eScanTrojan.Agent.24842
FireEyeTrojan.Agent.24842
McAfeeArtemis!D54F1CEB3D20
CylanceUnsafe
Cybereasonmalicious.b3d200
SymantecML.Attribute.HighConfidence
KasperskyTrojan.Win32.Pasta.aqdx
BitDefenderTrojan.Agent.24842
NANO-AntivirusTrojan.Win32.StartPage.danjwp
AvastWin32:Trojan-gen
TencentWin32.Trojan.Dropper.Wptf
Ad-AwareTrojan.Agent.24842
SophosIstbar (PUA)
ComodoMalware@#2qvcru8u3yltd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.lh
EmsisoftTrojan.Agent.24842 (B)
IkarusTrojan.Agent
GDataTrojan.Agent.24842
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
ArcabitTrojan.Agent.D610A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacTrojan.Agent.24842
APEXMalicious
YandexTrojan.Agent!o6iiuuU94ZE
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
WebrootPua.Supercool
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan.Agent.24842?

Trojan.Agent.24842 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment