Trojan

What is “Trojan.Win32.Agent2”?

Malware Removal

The Trojan.Win32.Agent2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent2 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the LokiLocker malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan.Win32.Agent2?


File Info:

name: C3AD08CD452F2F059483.mlw
path: /opt/CAPEv2/storage/binaries/453b601a489bfaeb91ed5d4aa00df8763657ae7a6090d23ba56cea0612c3646f
crc32: FB311A39
md5: c3ad08cd452f2f059483e941e0f36c08
sha1: 46066e30dc762f9a47ca3ce0b23fbbc5b3366756
sha256: 453b601a489bfaeb91ed5d4aa00df8763657ae7a6090d23ba56cea0612c3646f
sha512: 87a7328688b70415edaa664e918b6fa1ee3a9f6abe979b22ba1ee3580526fdd3fd89a78fc1ff965a9da5b447f08e37dfb44985be0c5c5dc4c725665ea05eb1fb
ssdeep: 3072:1VtQkxPq0APg7P/1X2NeaNxqBOhRBKLwotLlkSn4mMPB/BuX6vzTNkd7lnZLlmZi:rlR/1X6xqlkMM6qvPNkZLB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D346B9873F8468DF6BA1B7E5972D5264F36BC5B7B30CA3C1181312E0973AC4EA11762
sha3_384: 1d3c0f4a4c1830685bffbd5b5e056252ea308910e23d229c30d984c5a4f3d68e57fc8dd40fe281d9f457aa2a54aa617c
ep_bytes: 00000000000000000000000000000000
timestamp: 2104-08-17 20:22:39

Version Info:

0: [No Data]

Trojan.Win32.Agent2 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent2.4!c
ElasticWindows.Trojan.Generic
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.68824520
Cylanceunsafe
ZillyaTrojan.Agent2.Win32.33872
SangforRansom.Win32.Save.a
AlibabaRansom:MSIL/LokiLocker.bc2bebaf
Cybereasonmalicious.0dc762
CyrenW32/ABRisk.JCNC-3541
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Packed.Cdmip-9941726-0
KasperskyHEUR:Trojan.Win32.Agent2.gen
BitDefenderTrojan.GenericKD.68824520
MicroWorld-eScanTrojan.GenericKD.68824520
RisingRansom.Agent!1.D220 (CLASSIC)
EmsisoftTrojan.GenericKD.68824520 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKD.68824520
TrendMicroRansom_LokiLocker.R002C0DHO23
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c3ad08cd452f2f05
SophosMal/Generic-S
IkarusTrojan.Win32.Obsidium
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan[Ransom]/Win32.DCrypt.a
MicrosoftRansom:MSIL/LokiLocker.MK!MTB
ArcabitTrojan.Generic.D41A2DC8
ZoneAlarmHEUR:Trojan.Win32.Agent2.gen
GDataTrojan.GenericKD.68824520
GoogleDetected
McAfeeArtemis!C3AD08CD452F
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallRansom_LokiLocker.R002C0DHO23
TencentTrojan-Ransom.Win32.Agent.16000637
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Mabezat.Dam
FortinetW32/PossibleThreat!tr.ransom
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Agent2?

Trojan.Win32.Agent2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment