Spy Trojan

Should I remove “Trojan-Spy.Win64.Agent”?

Malware Removal

The Trojan-Spy.Win64.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win64.Agent virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win64.Agent?


File Info:

name: AC3D6F2BA622C144DD5B.mlw
path: /opt/CAPEv2/storage/binaries/72dd8fd0ab01a5305cb1a44508ca80cbf79ea9c423929452632f2dc7be56a199
crc32: 336EE05F
md5: ac3d6f2ba622c144dd5b5b70130b0eff
sha1: ea63ef33b87472b304d6a102b71d2a3aec142693
sha256: 72dd8fd0ab01a5305cb1a44508ca80cbf79ea9c423929452632f2dc7be56a199
sha512: b701daa00ff437f5245592b6fa37be9d5328c94757c15e8fc87211dce53f0ed67ebdb358e8bcc8bedde5ef069cfe0756c6961ff3c52174b08ac3597f4288763e
ssdeep: 49152:D2F4m+kSGWItoSrPD6QOWzSsuVAt+afpMgHgSt7Z9ZXJoavCeHi3jDGzQsJkOEhb:GLSmDwDsXtfH8sZFZYQu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154267E113CF42F31E5973A3644AFD7282B362E24D717CFE3483A86B499532D2EE1A159
sha3_384: 2dedf6dc4ba4a5134087da3519c3a0a103fe24eabb169c76d12071ff976f6af993c8acd24a45dd3a6275047c0830818c
ep_bytes: 83ec0cc7055835520001000000e8feb2
timestamp: 2021-12-27 06:49:34

Version Info:

0: [No Data]

Trojan-Spy.Win64.Agent also known as:

McAfeeGenericRXRL-MD!AC3D6F2BA622
CylanceUnsafe
SangforTrojan.Win64.Agent.gen
BitDefenderThetaGen:NN.ZexaCO.34212.@@Z@amKrgDc
KasperskyHEUR:Trojan-Spy.Win64.Agent.gen
AvastWin32:Malware-gen
ZillyaTrojan.Agent.Win64.10829
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.rh
SophosMal/Generic-S
IkarusTrojan-PSW.Discord
JiangminTrojanSpy.Agent.affz
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32BScope.TrojanSpy.Win64.Agent
TrendMicro-HouseCallTROJ_GEN.R002H06AH22
RisingSpyware.Agent!8.C6 (CLOUD)
AVGWin32:Malware-gen

How to remove Trojan-Spy.Win64.Agent?

Trojan-Spy.Win64.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment