Malware

About “Win32/Agent.ACHK” infection

Malware Removal

The Win32/Agent.ACHK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ACHK virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent.ACHK?


File Info:

name: 7058D93FEA8482E07DF8.mlw
path: /opt/CAPEv2/storage/binaries/49872b0aee25dfaafe09aaa2c5428cb6f530e0026d1d2f694f569d039f6f5ca0
crc32: D5FBD1E4
md5: 7058d93fea8482e07df8a22f5daf372d
sha1: 443d4743754197638d32e59550487055cdb5a857
sha256: 49872b0aee25dfaafe09aaa2c5428cb6f530e0026d1d2f694f569d039f6f5ca0
sha512: 614cc8d56216e1fe68190fb400781d819abdd2b7d91fc104799a71f7674c759a1d764a80aaaaafaf27ad130c476cb0857abada9a565e068b063668b6be1863d9
ssdeep: 98304:9NQZEtoRU+oxzbqERHu+EchxoEGtg56l4752tK8WwmOHEzf9Mpeph+g11G9uL/bI:9NQZooRU+oxzbqERHu+EchxoEGtg56l5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T135565CE7942361A3D4AE42B298D57A02BA639F37A3080DD335D0BD38D3A5F52095973F
sha3_384: cc325836a599812795b795916be36d046808af4615e6ed8e44114a12a568a6d5dac61b64d39b0b8418867d7e19f3aa3d
ep_bytes: 558bec837d0c017505e8c3050000ff75
timestamp: 2020-08-29 06:22:33

Version Info:

0: [No Data]

Win32/Agent.ACHK also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CoinLoader.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.7058d93fea8482e0
ALYacTrojan.GenericKD.72453836
Cylanceunsafe
VIPRETrojan.GenericKD.72453836
SangforTrojan.Win32.Agent.Vz1c
K7AntiVirusTrojan ( 00595f341 )
K7GWTrojan ( 00595f341 )
BitDefenderThetaGen:NN.ZedlaF.36804.@x6@aOqU@qfi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACHK
APEXMalicious
BitDefenderTrojan.GenericKD.72453836
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.72453836
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.140947e0
EmsisoftTrojan.GenericKD.72453836 (B)
F-SecureTrojan.TR/CoinLoader.wsjlh
ZillyaTrojan.Agent.Win32.2879903
Trapminesuspicious.low.ml.score
SophosMal/Generic-R
WebrootW32.Malware.Gen
VaristW32/ABRisk.XVAR-0126
AviraTR/CoinLoader.wsjlh
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.Generic.D4518ECC
ViRobotTrojan.Win.Z.Agent.6126104
GDataTrojan.GenericKD.72453836
GoogleDetected
AhnLab-V3Trojan/Win32.Coinloader.R349548
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R002H0CDJ24
RisingTrojan.Generic@AI.88 (RDML:CepKTo8EZx13rqOePdS+tQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.185932797.susgen
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/CoinLoader.wvQjg

How to remove Win32/Agent.ACHK?

Win32/Agent.ACHK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment