Trojan

Trojan.AgentWDCR.IFU malicious file

Malware Removal

The Trojan.AgentWDCR.IFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.IFU virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Trojan.AgentWDCR.IFU?


File Info:

crc32: C54FFFAC
md5: 8ed70ce6467219896cb4a066cb64b71b
name: 8ED70CE6467219896CB4A066CB64B71B.mlw
sha1: 76f0f5f515896eaefbc9f5c7e85f10c81b4b953f
sha256: a37856ea416f0723a1e3a61515878384cb5c33e1984114281956b660cef6d301
sha512: 955b462514fa549af5119ca9d87c17a2da703646657c4b121834ec354c5682f553ea795306d6b797520f64367acc242c36d7a4d7a1ee98ec8fc3fb2656ec6100
ssdeep: 1536:rsjAznbqg6Vo/OYR6NbF/X7RnRY4oLuafc5AhLqXDd3RIzlrwDLb0A:rskvWoG5bjY4oqRAhmX5BIzlaLb0A
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Trojan.AgentWDCR.IFU also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f3cdd1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.6246
CynetMalicious (score: 100)
ALYacTrojan.AgentWDCR.IFU
CylanceUnsafe
ZillyaTrojan.CryptXXX.Win32.677
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tovicrypt.381c9c02
K7GWTrojan ( 004f3cdd1 )
Cybereasonmalicious.646721
CyrenW32/S-b5a1ff1e!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32Win32/Filecoder.CryptProjectXXX.H
ZonerTrojan.Win32.45604
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.AgentWDCR.IFU
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Ransom.93696.D
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanTrojan.AgentWDCR.IFU
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.AgentWDCR.IFU
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34692.fy1@a0PKLFbQ
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-GJA!8ED70CE64672
FireEyeGeneric.mg.8ed70ce646721989
EmsisoftTrojan.AgentWDCR.IFU (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.CryptXXX.xw
AviraTR/Crypt.XPACK.sdlsn
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1B85EDF
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.AgentWDCR.IFU
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.AgentWDCR.IFU
AhnLab-V3Trojan/Win32.CryptXXX.R188553
Acronissuspicious
McAfeeRansomware-GJA!8ED70CE64672
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.3156691918
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Win32.Tovicrypt.a (CLOUD)
YandexTrojan.GenAsa!fV4lYBUPwBQ
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.AgentWDCR.IFU?

Trojan.AgentWDCR.IFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment