Trojan

What is “Trojan:Win32/Samcrex.A”?

Malware Removal

The Trojan:Win32/Samcrex.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Samcrex.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Executed a sysinternals tool
  • CAPE detected the mimikatz malware family
  • Clears Windows events or logs
  • Creates a copy of itself
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Created a service that was not started
  • PSExec was executed
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Samcrex.A?


File Info:

name: 59C3F3F99F44029DE812.mlw
path: /opt/CAPEv2/storage/binaries/32efb1eb360cda726f0eb7647d1963adf37dada4b1a4b5ec486c88bfa1f21471
crc32: DB3B089B
md5: 59c3f3f99f44029de81293b1e7c37ed2
sha1: fb07496900468529719f07ed4b7432ece97a8d3d
sha256: 32efb1eb360cda726f0eb7647d1963adf37dada4b1a4b5ec486c88bfa1f21471
sha512: 9b3bd8a76d754bf9c899111be986c4fd6d14f6993a9a0e3dcd9b4a76c0f7764ac8798f5cbc7a0467c1562638d85bf52f627bd32c125f587b1e838beaf03c8a0e
ssdeep: 49152:aIuQjMgjzus3wLNlDXjUoXFhKoT2iG6xQQqOeaGcWRrLy3pN+:a1bgjyQwhlDFEi5Qt7aGdRrLy5N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193852396B9C180B2E4E344749CF8DA754CAC7A300B212ADFB7E0573D5E261D06736EA6
sha3_384: c49b408261e5a02887b9054091a575bd8da4c699fabb721f955458c7fd40be965c91b40b02a6b3515b0ac33f7319b879
ep_bytes: e84c040000e98efeffff558bec6a00ff
timestamp: 2017-12-27 11:39:22

Version Info:

0: [No Data]

Trojan:Win32/Samcrex.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OlympicDestroyer.i!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.84967
FireEyeGeneric.mg.59c3f3f99f44029d
SkyhighBehavesLike.Win32.Generic.tc
ALYacBackdoor.Agent.1863680
Cylanceunsafe
ZillyaTrojan.Agent.Win32.877452
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005273791 )
AlibabaTrojanPSW:Win32/Samcrex.f32af2c2
K7GWTrojan ( 005273791 )
Cybereasonmalicious.900468
BitDefenderThetaGen:NN.ZexaF.36744.XzW@a8zouSbi
VirITBackdoor.Win32.Bot.ESQ
SymantecTrojan.Olydestroy
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/OlympicDestroyer.A
APEXMalicious
ClamAVWin.Trojan.Agent-6447406-0
KasperskyTrojan-PSW.Win32.Agent.tgql
BitDefenderTrojan.GenericKDZ.84967
NANO-AntivirusRiskware.Win32.Bot.exxyzi
AvastWin32:OlympicDestroy-B [Apt]
TencentMalware.Win32.Gencirc.115de0d5
EmsisoftTrojan.GenericKDZ.84967 (B)
F-SecureTrojan.TR/Crypt.ZPACK.zljum
DrWebBackDoor.IRC.Bot.3188
VIPRETrojan.GenericKDZ.84967
TrendMicroTROJ_OlympicDestroyer.A
Trapminemalicious.high.ml.score
SophosMal/Olydest-A
IkarusTrojan.Win32.Olympicdestroyer
GDataWin32.Trojan.OlympicDestroyer.A
JiangminTrojan.PSW.Agent.uu
WebrootW32.Olympicdestroyer
GoogleDetected
AviraTR/Crypt.ZPACK.zljum
VaristW32/OlympicDestroyer.A.gen!Eldorado
Antiy-AVLTrojan[APT]/Win32.Hades
Kingsoftmalware.kb.a.1000
XcitiumMalware@#1eon2fudvkbke
ArcabitTrojan.Generic.D14BE7
ViRobotDropper.Agent.1863680
ZoneAlarmTrojan-PSW.Win32.Agent.tgql
MicrosoftTrojan:Win32/Samcrex.A
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.PyAgent.R220091
McAfeeTrojan-WWVipe!59C3F3F99F44
MAXmalware (ai score=100)
VBA32Backdoor.IRC.Bot
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_OlympicDestroyer.A
RisingTrojan.Samcrex!8.F3F2 (TFE:5:kBAxSElIecG)
YandexTrojan.GenAsa!ZJxpbN0JYJA
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.12043138.susgen
FortinetW32/OlympicDestroyer.A!tr
AVGWin32:OlympicDestroy-B [Apt]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Samcrex.A?

Trojan:Win32/Samcrex.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment