Trojan

What is “Trojan.AgentWDCR.YZA”?

Malware Removal

The Trojan.AgentWDCR.YZA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.YZA virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.AgentWDCR.YZA?


File Info:

crc32: EF617BF4
md5: 9cb1c1a78ce3efe57eef5f128b43710a
name: 3.rar
sha1: 4310544fbd1b01e9decfb75e5a25592d822447c5
sha256: 111aff9c3d2d5d21d868760f9c758054f506c8af18b7c65e7ea351a977453128
sha512: 2ac56187f2b879b14a30283e8c67667e83af5274f4582a797e70c3572784fb3e8f6b2576b4bb1833047dc557e2877504c52f42eb8705194886e65ec50460808c
ssdeep: 6144:jIIcrXQ4S33w614mazUBHfSdocWYD248T+tvt2Dnsj:NcrNS33L10QdrX5T+tkDn8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.AgentWDCR.YZA also known as:

MicroWorld-eScanTrojan.AgentWDCR.YZA
FireEyeTrojan.AgentWDCR.YZA
CAT-QuickHealTrojan.BAT
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 005291791 )
BitDefenderTrojan.AgentWDCR.YZA
K7GWTrojan-Downloader ( 005291791 )
Cybereasonmalicious.78ce3e
ArcabitTrojan.AgentWDCR.YZA
BaiduBAT.Trojan-Downloader.Agent.al
F-ProtW32/Agent.NBWK
APEXMalicious
AvastSFX:Agent-E [Trj]
ClamAVWin.Packed.njRAT-7086562-0
KasperskyTrojan.Win32.Agentb.jvkn
AlibabaTrojanDownloader:Win32/Agentb.59e26270
NANO-AntivirusTrojan.Script.Miner.fkfjri
ViRobotTrojan.Win32.Z.Strictor.302551
AegisLabTrojan.Win32.Agentb.4!c
RisingTrojan.CoinMiner/BAT!1.BA78 (KTSE)
Endgamemalicious (high confidence)
EmsisoftTrojan.AgentWDCR.YZA (B)
ComodoMalware@#5k5xfynz04cv
F-SecureTrojan.TR/Dldr.Agent.ziezq
DrWebBAT.BtcMine.34
TrendMicroTROJ_GEN.R03BC0PLD19
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dh
FortinetW32/Asym!tr
Trapminesuspicious.low.ml.score
SophosMal/Generic-L
IkarusTrojan-Downloader.Win32.Agent
CyrenW32/Trojan.EQDA-4469
WebrootW32.Trojan.Win64.Bitminer
AviraTR/Dldr.Agent.ziezq
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Generic!rfn
ZoneAlarmTrojan.Win32.Agentb.jvkn
AhnLab-V3Trojan/Win32.Tiggre.C3624069
VBA32Trojan.BAT.Asym
ALYacTrojan.BAT.Asym
Ad-AwareTrojan.AgentWDCR.YZA
MalwarebytesTrojan.Downloader
PandaTrj/wlt.F
ZonerTrojan.VBS.87574
ESET-NOD32Win32/TrojanDownloader.Agent.DVC
TrendMicro-HouseCallTROJ_GEN.R03BC0PLD19
TencentWin32.Trojan.Agentb.Hxgb
GDataWin32.Trojan.Agent.950UKB
AVGSFX:Agent-E [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.008

How to remove Trojan.AgentWDCR.YZA?

Trojan.AgentWDCR.YZA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment