Trojan

Trojan.AgentWDCR.AAXW removal tips

Malware Removal

The Trojan.AgentWDCR.AAXW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.AAXW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan.AgentWDCR.AAXW?


File Info:

name: 6825DE0975EE6F6E7BD1.mlw
path: /opt/CAPEv2/storage/binaries/571c4e3bef4c9278871d2ff3d6121eb257fd3911cf71dada9da115e27b61be01
crc32: 85F80DF8
md5: 6825de0975ee6f6e7bd15b4c9a89dcaa
sha1: 713bab027d94831f9f575e672b3efb1df5aab299
sha256: 571c4e3bef4c9278871d2ff3d6121eb257fd3911cf71dada9da115e27b61be01
sha512: d506e3ce7d55b0abcf5d7f40f5bcca13be113295e8a631a61ce5749eb6b25a973429459e01fb0940981eef785561a73117d300bef38a105a48dffda7911d5363
ssdeep: 768:VzdYgmIbPzwABgWR1vW3fLZtpe5Rq7KbC:VzMIbPzwABgWR1vEpz7Ku
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172F2E733F5E764D3D8791DF4EE2E8FA9316F2C101A54D91BA102B34F11B26A06DAE1D8
sha3_384: 16d67d07568c878707685a8178b179109f6162651868802d28eed09fa6d21e2925d58b8b572d7162ac466605a6a21111
ep_bytes: 681c1a4000e8f0ffffff000000000000
timestamp: 2020-03-18 23:30:43

Version Info:

Translation: 0x0400 0x04b0
Comments: GJ
CompanyName: SAMT
FileDescription: GJ
LegalCopyright: DDSANNO
LegalTrademarks: BERMUDA"
ProductName: GJ
FileVersion: 1.00
ProductVersion: 1.00
InternalName: INDSVBTE
OriginalFilename: INDSVBTE.exe

Trojan.AgentWDCR.AAXW also known as:

LionicTrojan.Win32.VB.i!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.22388
MicroWorld-eScanTrojan.AgentWDCR.AAXW
FireEyeGeneric.mg.6825de0975ee6f6e
McAfeeFareit-FRJ!6825DE0975EE
CylanceUnsafe
ZillyaTrojan.Injector.Win32.693803
SangforTrojan.Win32.Skeeyah.A
K7AntiVirusTrojan ( 005630031 )
AlibabaTrojanPSW:Win32/Kryptik.7e1054a6
K7GWTrojan ( 005630031 )
Cybereasonmalicious.975ee6
ArcabitTrojan.AgentWDCR.AAXW
BitDefenderThetaGen:NN.ZevbaF.34232.cm0@aWyUCsiG
VirITTrojan.Win32.Injector.CBQ
CyrenW32/VBKrypt.AFU.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Agent.EYK
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.WLDC
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.VB.qpj
BitDefenderTrojan.AgentWDCR.AAXW
NANO-AntivirusTrojan.Win32.VB.hgckyj
AvastOther:Malware-gen [Trj]
RisingDownloader.Agent!8.B23 (CLOUD)
Ad-AwareTrojan.AgentWDCR.AAXW
SophosMal/Generic-S + Troj/Fareit-KCD
ComodoMalware@#2wotj8obnv7y0
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.FAREIT.WLDC
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
EmsisoftTrojan.AgentWDCR.AAXW (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.VB.jx
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.301D711
GridinsoftRansom.Win32.Skeeyah.sa
MicrosoftTrojan:Win32/Skeeyah.A!MTB
ZoneAlarmTrojan-PSW.Win32.VB.qpj
GDataWin32.Trojan.Agent.8RZD6D
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.VBKrypt.C4073848
MalwarebytesTrojan.GuLoader
APEXMalicious
YandexTrojan.GenAsa!xavGSl8mo9k
IkarusTrojan.VB.Crypt
FortinetW32/Injector.ELCV!tr
AVGOther:Malware-gen [Trj]
PandaTrj/WLT.F
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AgentWDCR.AAXW?

Trojan.AgentWDCR.AAXW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment