Trojan

What is “Trojan.AgentWDCR.AXZ”?

Malware Removal

The Trojan.AgentWDCR.AXZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.AXZ virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.AgentWDCR.AXZ?


File Info:

name: 98797D4ECFA53276B65E.mlw
path: /opt/CAPEv2/storage/binaries/a1677f2c63f78da6dad90b1689707c71d14d5d1e6a66208346055d0bdd0871b3
crc32: 9B26F0D7
md5: 98797d4ecfa53276b65e252844db3e53
sha1: fe1ffdfa7398a9732a778fbfa241e89bd37d121a
sha256: a1677f2c63f78da6dad90b1689707c71d14d5d1e6a66208346055d0bdd0871b3
sha512: a6edd8460fcdeb3b4a635dba59c1cfe05d0c087645312210e34bb32637bc94c97614335c108f737859d3830d88ca4c931cd8924655fce78f261794be76c6ae9d
ssdeep: 192:+uezszppVZ745F2N0RL4iwO09yrjdTJT5WxyHgwl/FTg/K5v8bQ/:+My+N0RM2jdt2yHgti5vP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124925252E3D308E8E15A46F11DFFB3B1A1617492E6368F8E1FC1B5360A832D644BD68D
sha3_384: 10926b97f305099bb9a15db7297f2e61fe61f9b20d217873439247c38f49893093f623aadae45428b42e10c4a6bdb2a0
ep_bytes: 558bec33c0b918000000504975fcff15
timestamp: 2002-04-21 12:36:13

Version Info:

0: [No Data]

Trojan.AgentWDCR.AXZ also known as:

BkavW32.FamVT.GeND.Trojan
tehtrisGeneric.Malware
DrWebTrojan.DownLoader11.7243
MicroWorld-eScanTrojan.AgentWDCR.AXZ
FireEyeGeneric.mg.98797d4ecfa53276
CAT-QuickHealTrojanDownloader.Upatre.V4
McAfeeDownloader-FABU
MalwarebytesTrojan.Downloader.UPT
VIPRETrojan.AgentWDCR.AXZ
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
BitDefenderTrojan.AgentWDCR.AXZ
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.ecfa53
BitDefenderThetaGen:NN.ZexaF.34806.bqX@aKK9Wogi
VirITTrojan.Win32.Generic.DKJ
CyrenW32/Trojan.XYNH-6475
SymantecTrojan.Zbot
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan-Spy.Win32.Zbot.shyq
NANO-AntivirusTrojan.Win32.Zbot.cxqhcu
RisingDownloader.Waski!1.A489 (CLASSIC)
Ad-AwareTrojan.AgentWDCR.AXZ
SophosML/PE-A + Troj/Agent-AGYI
ComodoTrojWare.Win32.Kryptik.CBXB@5a837k
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaTrojan.Zbot.Win32.154498
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionDownloader-FSH!98797D4ECFA5
Trapminemalicious.high.ml.score
EmsisoftTrojan.AgentWDCR.AXZ (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.edwv
AviraTR/Kazy.377586
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftTrojan:Win32/Zbot.SIBE12!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Necurs
ZoneAlarmTrojan-Spy.Win32.Zbot.shyq
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R106241
VBA32TrojanSpy.Zbot
ALYacTrojan.AgentWDCR.AXZ
CylanceUnsafe
PandaGeneric Malware
APEXMalicious
TencentMalware.Win32.Gencirc.10b2e791
YandexTrojanSpy.Zbot!LOhpFxEGRmU
IkarusTrojan.Win32.Danglo
FortinetW32/Kryptik.GQIX!tr
AVGWin32:Dropper-NWT [Trj]
AvastWin32:Dropper-NWT [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AgentWDCR.AXZ?

Trojan.AgentWDCR.AXZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment