Trojan

Trojan.AgentWDCR.TCW removal tips

Malware Removal

The Trojan.AgentWDCR.TCW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.TCW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine Trojan.AgentWDCR.TCW?


File Info:

name: 2C15BB0EBAE12F4419DB.mlw
path: /opt/CAPEv2/storage/binaries/ba8a6d564681df853fa4609b38611bc5d9b3caab44c419cfd7b0c2580e5763c5
crc32: B345313B
md5: 2c15bb0ebae12f4419db7613a2014c46
sha1: 25d0b167522bb6bfa0a0a412e20743298e179edd
sha256: ba8a6d564681df853fa4609b38611bc5d9b3caab44c419cfd7b0c2580e5763c5
sha512: f4d4cdbbb6a82ad13e264ee3c14380251c0b378e535541b1120666ec3d5da1d4941c830ae5a2895e0ff9c4b3033ed5ba449585c8f8874e1c5b76f9ad11a0e276
ssdeep: 6144:fB4R6t96sXhmdl2vICYyA5etEabaMG6C62KjQQ+SIymkp6f7wpOGqdXXS:fBtXXho2EyA5tMG6CblhSICAUIGY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180E4C25E2910E5B7FA8012B0B64581AD85FA2C3EC07080BDFED2BB56BDF65A5C476207
sha3_384: 9dc351c6d01c685a33d338786243a8cc0996ca47bd50ebb6e1eed174cebf6e13c39ce60a8489aa5db159a8eaf3fb6368
ep_bytes: 685c1a4000e8eeffffff000000000000
timestamp: 2016-10-15 15:20:12

Version Info:

Translation: 0x0409 0x04b0
ProductName: enetimeklitoris
FileVersion: 1.00
ProductVersion: 1.00
InternalName: talekanalentriacids
OriginalFilename: talekanalentriacids.exe

Trojan.AgentWDCR.TCW also known as:

LionicTrojan.Win32.Fareit.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AgentWDCR.TCW
FireEyeGeneric.mg.2c15bb0ebae12f44
McAfeeGeneric.bua
CylanceUnsafe
VIPRETrojan.AgentWDCR.TCW
SangforVISUAL BASIC4
K7AntiVirusTrojan ( 00552d5a1 )
AlibabaTrojanPSW:Win32/Fareit.30a2a27a
K7GWTrojan ( 00552d5a1 )
Cybereasonmalicious.ebae12
VirITTrojan.Win32.VBGenus.EV
CyrenW32/Wacatac.N.gen!Eldorado
SymantecPacked.Generic.535
ESET-NOD32Win32/PSW.Fareit.A
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Fareit.faer
BitDefenderTrojan.AgentWDCR.TCW
NANO-AntivirusTrojan.Win32.Fareit.ftynct
AvastOther:Malware-gen [Trj]
RisingBackdoor.Androm!8.113 (KTSE)
Ad-AwareTrojan.AgentWDCR.TCW
EmsisoftTrojan.AgentWDCR.TCW (B)
ComodoMalware@#8ra20jqe7z4n
F-SecureTrojan.TR/AD.VBCryptor.hxucx
DrWebTrojan.Inject3.20089
ZillyaTrojan.Fareit.Win32.34266
TrendMicroTrojan.Win32.MALREP.THFAHAI
McAfee-GW-EditionGeneric.bua
SophosMal/Generic-R + Mal/FareitVB-X
GDataWin32.Trojan.Agent.NEVBF7
JiangminTrojan.PSW.Fareit.zva
AviraTR/AD.VBCryptor.hxucx
Antiy-AVLTrojan[PSW]/Win32.Fareit
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3Trojan/Win32.Androm.R282756
BitDefenderThetaGen:NN.ZevbaF.34806.Om0@am1igafO
ALYacTrojan.AgentWDCR.TCW
MAXmalware (ai score=100)
VBA32TrojanPSW.Fareit
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTrojan.Win32.MALREP.THFAHAI
TencentWin32.Trojan.Inject.Auto
YandexTrojan.Igent.bRX5e1.1
IkarusTrojan.VB.Agent
MaxSecureTrojan.Malware.74516504.susgen
FortinetW32/Fareit.DNPW!tr.pws
AVGOther:Malware-gen [Trj]
PandaTrj/WLT.E
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AgentWDCR.TCW?

Trojan.AgentWDCR.TCW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment