Trojan

How to remove “Trojan.Agentcrypt”?

Malware Removal

The Trojan.Agentcrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agentcrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
zipansion.com
hurirk.net
a.tomx.xyz

How to determine Trojan.Agentcrypt?


File Info:

crc32: 3A31539C
md5: 027b5a4d380808907bf4c96f8ce35479
name: 027B5A4D380808907BF4C96F8CE35479.mlw
sha1: 4b59474f27b6907cff50e417a686505212dfc83b
sha256: b2656488ebbf10ecc5529117ad5125f41aec660947e5e0e0b0fd8f2ab18b1984
sha512: f05fc6214a9d4fbd1ec1320c559748d1bd709ad3d341f4b766a9dce6115118e76941e294f4088cc61aff705effc4830dcc978cde0290ce244fcc3aeb2be7f62e
ssdeep: 24576:J385y/3I5VLIgyaujUpbu6v3OokHnd8CxCMk88eKBY0vQl/qPtMY0gYGoYYVMbQ:zgVvuIpbu5yLMZwoD26tMc
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Agentcrypt also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
ClamAVWin.Packed.Razy-9820160-0
CAT-QuickHealTrojan.Agentcrypt
ALYacGen:Variant.Razy.381404
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan ( 0056f44b1 )
K7AntiVirusTrojan ( 0056f44b1 )
CyrenW32/Kryptik.CYM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKAM
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Khalesi.vho
BitDefenderGen:Variant.Razy.381404
MicroWorld-eScanGen:Variant.Razy.381404
Ad-AwareGen:Variant.Razy.381404
SophosTroj/Agent-BGPN
BitDefenderThetaAI:Packer.A951E69C1E
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
FireEyeGeneric.mg.027b5a4d38080890
EmsisoftGen:Variant.Razy.381404 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Khalesi.bdqa
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/AgentCrypt.SM!MTB
GDataGen:Variant.Razy.381404
AhnLab-V3Malware/Win.Generic.R373678
McAfeeGenericRXAA-AA!027B5A4D3808
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Khalesi.VHO!tr
AVGWin32:Trojan-gen

How to remove Trojan.Agentcrypt?

Trojan.Agentcrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment