Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

UDS:Rootkit.Win64.Agent malicious file

Published Sep 15, 2023 Rootkit category 3 min read
Report context

What to verify before removal

This report keeps UDS:Rootkit.Win64.Agent malicious file in the active library because the detection has enough technical context to support a careful second-opinion scan and cleanup decision.

Start by comparing the local file name with 375284C7931FFD6CC73E.mlw, then review the behavior notes for persistence entries, dropped files, unusual processes, and browser or network changes. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
375284C7931FFD6CC73E.mlw
  • Compare the suspicious file name with 375284C7931FFD6CC73E.mlw.
  • Confirm the detection name matches UDS:Rootkit.Win64.Agent malicious file before removing related files.
  • Review the report for persistence entries, dropped files, unusual processes, and browser or network changes so the cleanup is based on observed behavior, not only the label.
  • Run a full scan, quarantine confirmed detections, and restart before signing back in to sensitive accounts.

The UDS:Rootkit.Win64.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What UDS:Rootkit.Win64.Agent virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine UDS:Rootkit.Win64.Agent?


File Info:

name: 375284C7931FFD6CC73E.mlw
path: /opt/CAPEv2/storage/binaries/9b0937019509aa58710b2a3d31918feee495c7e0c48db8b4ddef3e247ce16450
crc32: AC42F467
md5: 375284c7931ffd6cc73eb50f2bc395d4
sha1: 3dc7a856004e0109b6bfd73c96ec8035b3b834ab
sha256: 9b0937019509aa58710b2a3d31918feee495c7e0c48db8b4ddef3e247ce16450
sha512: 3f766781a4b06eadbe34853546c6c509b94ce215e41e7e934f3de87124a6f38dbc0f48aa752fcbb05ff027b7136d7401c8ca9dba5eb6187b45d11c21fc715b91
ssdeep: 12288:z0cP4FCbcvjbks3adMJivj6rgwPShwL1hs3JQbSQuirAWU/1k8J/oboS:z9gfv3Z3QMJqjpfhwRGGSQM3/VJ/o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9E423DB01B1EE35D252B1BEAB069F954E491046FA632898B9D084CD8F1DF8F1C5EE31
sha3_384: cc8925c552cb5a38409dff56bc68b28d11b63cb932a45e73b51ddf2ece04ebec569cea3caf7c5f4ca87f635516786467
ep_bytes: 60be003064008dbe00e0dbff5789e58d
timestamp: 2023-08-26 06:37:02

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

UDS:Rootkit.Win64.Agent also known as:

Bkav W32.AIDetectMalware
tehtris Generic.Malware
Cynet Malicious (score: 100)
FireEye Generic.mg.375284c7931ffd6c
Malwarebytes PUP.Optional.ChinAd
Sangfor Virus.Win32.Save.a
K7AntiVirus Trojan ( 005930da1 )
K7GW Trojan ( 005930da1 )
Cybereason malicious.6004e0
BitDefenderTheta Gen:NN.ZexaF.36662.QmKfaGqXBocb
Cyren W32/Trojan.GRW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/Packed.BlackMoon.A suspicious
APEX Malicious
ClamAV Win.Dropper.Tiggre-9845940-0
Kaspersky UDS:Rootkit.Win64.Agent.gen
BitDefender Gen:Variant.Application.Graftor.795801
MicroWorld-eScan Gen:Variant.Application.Graftor.795801
Avast Win32:RATX-gen [Trj]
Emsisoft Application.Generic (A)
DrWeb Trojan.Rootkit.22113
VIPRE Gen:Variant.Application.Graftor.795801
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
Trapmine malicious.high.ml.score
Sophos Generic ML PUA (PUA)
Ikarus PUA.BlackMoon
GData Win32.Application.PSE.1ETEWJE
Antiy-AVL Trojan/Win32.Blamon.a
Arcabit Trojan.Application.Graftor.DC2499
ZoneAlarm VHO:Rootkit.Win64.Agent.gen
Microsoft PUA:Win32/Puwaders.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.R601178
VBA32 BScope.Trojan.Blamon
ALYac Gen:Variant.Application.Graftor.795801
MAX malware (ai score=71)
Cylance unsafe
Rising Trojan.MalCert!1.BCF8 (CLASSIC)
SentinelOne Static AI – Malicious PE
MaxSecure Dropper.Dinwod.frindll
Fortinet W32/CoinMiner.ESFJ!tr
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS

How to remove UDS:Rootkit.Win64.Agent?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.