Trojan

Trojan:Win32/AgentCrypt!pz (file analysis)

Malware Removal

The Trojan:Win32/AgentCrypt!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AgentCrypt!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/AgentCrypt!pz?


File Info:

name: 560C9C7879DFE352A6A9.mlw
path: /opt/CAPEv2/storage/binaries/ffe61b7eb20533d002e1278f6010e5657fbdb4e28639f605c1da199566015d66
crc32: F83412B5
md5: 560c9c7879dfe352a6a9d16c3515eb93
sha1: 8e6fe9fc78bf1bc5778fb8fdb831a51bbffdd752
sha256: ffe61b7eb20533d002e1278f6010e5657fbdb4e28639f605c1da199566015d66
sha512: 92e832d313267c6a34baead7d61549738b3f2c578027eadd99e59078fbc76242fc2a62c8522ba071a4161a172f09e18367adac592ce344a8471bb765bbbd3174
ssdeep: 49152:B2IQ8QdMfJCs5q5XJR7S9TmJSz3NxcW/T26tM3FCU19s2ppmSVu63Yu/b4AovIWr:B2IQCRCs5+sT6Sz9f2Sas2PDU635+v2O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AF5335A29759D46C6270AFAAAD6F29AE0A72C133D17F41DF0C2F7016BB0D004FF2A55
sha3_384: 3dbfc20216662e6e6e3551542b01ebd39d31803dc065d5fa913b54e1acbe1a0cea46e2dab853be3cc23f4d86970a35ae
ep_bytes: b8000000005629d289ca83ec04c70424
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/AgentCrypt!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Khalesi.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.VirLock.135
ClamAVWin.Packed.Razy-9820160-0
FireEyeGeneric.mg.560c9c7879dfe352
SkyhighBehavesLike.Win32.Generic.wc
McAfeeGenericRXAA-AA!560C9C7879DF
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057ed941 )
AlibabaTrojan:Win32/AgentCrypt.98071d95
K7GWTrojan ( 0057ed941 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ransom.VirLock.135
BitDefenderThetaGen:NN.ZexaF.36744.qlZ@aeMDDNb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HTAQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Khalesi.vho
BitDefenderGen:Variant.Ransom.VirLock.135
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Khalesi.fa
EmsisoftGen:Variant.Ransom.VirLock.135 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Packed2.43250
VIPREGen:Variant.Ransom.VirLock.135
SophosTroj/Agent-BGPN
IkarusTrojan.Win32.Injector
JiangminTrojan.Copak.aff
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/AgentCrypt!pz
ZoneAlarmHEUR:Trojan.Win32.Khalesi.vho
GDataGen:Variant.Ransom.VirLock.135
VaristW32/Razy.IZ.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R373678
ALYacGen:Variant.Ransom.VirLock.135
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Khalesi.VHO!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.c78bf1
DeepInstinctMALICIOUS

How to remove Trojan:Win32/AgentCrypt!pz?

Trojan:Win32/AgentCrypt!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment