Trojan

Trojan.Agent.5517479C (file analysis)

Malware Removal

The Trojan.Agent.5517479C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.5517479C virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.5517479C?


File Info:

crc32: 8D883C04
md5: e52394c2ede376c0018193b4cd93e31c
name: winrar.exe
sha1: edc935ea87bd46d30cb8c047153d442cc57177d6
sha256: 5ec747f8f31070ce2367cea19e92ee7c6dff787f08bbefa7421606d60dd3d216
sha512: 3a8f934111041fd629df8ee45b47905ef368298cf2ad2efce1abf533eb48c575af017049d9c9b469fb161beb8e271c3a080f08c43c7cd2f7871091985ffbe8c2
ssdeep: 98304:KH6ip8Z83EerQliRyPTto2sqwQUxXn2MvnuoCCt0CrIJ0mi5/8W0:KaGE83EerQayPZo2sqR432M/uoC20can
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 Alexander Roshal 1993-2017
InternalName: WinRAR
FileVersion: 5.50.1
CompanyName: Alexander Roshal
ProductName: WinRAR
ProductVersion: 5.50.1
FileDescription: WinRAR x538bx7f29x6587x4ef6x7ba1x7406x5668
OriginalFilename: WinRAR.exe
Translation: 0x0804 0x03a8

Trojan.Agent.5517479C also known as:

ALYacTrojan.Agent.5517479C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
F-ProtW32/Oficla.K.gen!Eldorado
TrendMicro-HouseCallTROJ_GEN.R002C0PAG20
GDataWin32.Trojan.Agent.L7524Y
AlibabaTrojan:Win32/Tiggre.840f46de
AegisLabTrojan.Win32.Generic.4!c
APEXMalicious
SophosMal/Generic-S
ComodoMalware@#23l96rdpe82la
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R002C0PAG20
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
CyrenW32/Oficla.K.gen!Eldorado
MaxSecureTrojan.Malware.11618911.susgen
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Tiggre!plock
McAfeeArtemis!E52394C2EDE3
IkarusTrojan.Win32.Scar
eGambitUnsafe.AI_Score_96%
FortinetPossibleThreat
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Agent.5517479C?

Trojan.Agent.5517479C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment