Trojan

Trojan.AgentWDCR.YYR removal guide

Malware Removal

The Trojan.AgentWDCR.YYR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.YYR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan.AgentWDCR.YYR?


File Info:

name: 759B61B659465F8D1935.mlw
path: /opt/CAPEv2/storage/binaries/441fb00795938bc0ecf4113aca8ed5bb28ff72e1c82c13dc0390b2356fd64a8c
crc32: D6A55AA1
md5: 759b61b659465f8d19352eaef000ed9d
sha1: 3cbeef249579931f8992d466db1d572aa02c8b20
sha256: 441fb00795938bc0ecf4113aca8ed5bb28ff72e1c82c13dc0390b2356fd64a8c
sha512: 00fcd946670ca58573858a398eae9d1cfc9798299732c5e1056b64a6ee1a702b6ed393029bfa848e6d5423fc01ed0c6bf6eb109b2c73fd05af45b7c1a593531b
ssdeep: 1536:KVPqPd1vPo6l6zRayXwAPC46O1nmgLq3gtS:K9Kd1vP9l6laCPp9meq6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B736C383AFA1029F273EF7A4FE47596DA6FB7732A07682E109103474623981DDD153A
sha3_384: 719ed4c744ee1cc619d10dbf80526b418ec3144b6ce4c3e724802b7edbebc44427c95eb68b5ddd804e92fcc753d33875
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-12-07 18:12:15

Version Info:

Translation: 0x0000 0x04b0
Comments: Host Process for Windows Tasks
CompanyName: Intel Corporation
FileDescription: Host Process for Windows Tasks
FileVersion: 8.15.1.3308
InternalName: taskhost.exe
LegalCopyright: Copyright 1996 - 2006. Intel Corporation
OriginalFilename: taskhost.exe
ProductName: Intel(R) Common User Interface
ProductVersion: 8.15.1.3308
Assembly Version: 8.15.1.3308

Trojan.AgentWDCR.YYR also known as:

LionicTrojan.MSIL.RRAT.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AgentWDCR.YYR
FireEyeGeneric.mg.759b61b659465f8d
McAfeeGenericRXJE-RB!759B61B65946
CylanceUnsafe
ZillyaTrojan.Injector.Win32.672619
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00521db01 )
AlibabaTrojan:MSIL/Skeeyah.fa66f293
K7GWTrojan ( 00521db01 )
Cybereasonmalicious.659465
BitDefenderThetaGen:NN.ZemsilF.34084.em0@aGgeSVb
CyrenW32/MSIL_RRat.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32MSIL/Agent.APN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-7172068-0
KasperskyHEUR:Trojan.MSIL.RRAT.gen
BitDefenderTrojan.AgentWDCR.YYR
NANO-AntivirusTrojan.Win32.RevetRat.glllmm
SUPERAntiSpywareBackdoor.RevengeRAT/Variant
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Rrat.Ahyp
Ad-AwareTrojan.AgentWDCR.YYR
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#o5yxus9u22v4
DrWebBackDoor.RevetRat.2
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.MSIL.RRAT.A
McAfee-GW-EditionGenericRXJE-RB!759B61B65946
EmsisoftTrojan.AgentWDCR.YYR (B)
IkarusTrojan-Spy.Agent
GDataWin32.Trojan.Agent.T6IQ6G
JiangminTrojan.MSIL.ofuy
AviraTR/Agent.vihhx
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2D59A33
MicrosoftTrojan:Win32/Skeeyah.A!MTB
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C3610397
VBA32TScope.Trojan.MSIL
ALYacTrojan.MSIL.Agent
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallBackdoor.MSIL.RRAT.A
YandexTrojan.RRAT!yz08XQDcnAc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74242025.susgen
FortinetW32/Injector.ABM!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/WLT.F
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AgentWDCR.YYR?

Trojan.AgentWDCR.YYR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment