Malware

Win32/Agent.ACSC removal tips

Malware Removal

The Win32/Agent.ACSC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ACSC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Agent.ACSC?


File Info:

name: DC5D776E3AB191771F73.mlw
path: /opt/CAPEv2/storage/binaries/d5738accfbf7b2f64b3739d46e306fd4a4467d7b855872b95a2a485c95a7a7fa
crc32: 33AB98FB
md5: dc5d776e3ab191771f73a1ae59f2549e
sha1: e5116b5a6db0a5226d29f38fc1c7bb81b3f681c0
sha256: d5738accfbf7b2f64b3739d46e306fd4a4467d7b855872b95a2a485c95a7a7fa
sha512: dc3233faf752105698e79eb9b33dd0dc399ec2169aa78dd6c7739a0eca318fedf37e2e84d1a3a30d0de922ae69e4acc82b69291b3f1508076388651810a16c52
ssdeep: 6144:l7Qnj/s5uZeJkR/tWmZdjbOVKR76ESlvQPt/OCXKVmg7lneibgZASei0HKd8+Hky:k/kuZeJux5EqwO7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137542A12B925D030D96091767A6A7FB28499A8397B6445CBB7C08F33D1921F77C32F3A
sha3_384: 87f0e89ea468e791292f439408bde68ae412f0baeda51da60eb23e7235906559c653d26bb044753113f74ede796a9597
ep_bytes: e822060000e97afeffff558bec6a00ff
timestamp: 2021-03-29 11:48:49

Version Info:

0: [No Data]

Win32/Agent.ACSC also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38123044
FireEyeGeneric.mg.dc5d776e3ab19177
McAfeeGenericRXOM-TQ!DC5D776E3AB1
CylanceUnsafe
K7AntiVirusTrojan ( 0057704f1 )
AlibabaTrojan:Win32/MalwareX.5c94a915
K7GWTrojan ( 0057704f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACSC
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
BitDefenderTrojan.GenericKD.38123044
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKD.38123044
EmsisoftTrojan.GenericKD.38123044 (B)
McAfee-GW-EditionGenericRXOM-TQ!DC5D776E3AB1
SophosMal/Generic-S
APEXMalicious
GDataTrojan.GenericKD.38123044
AviraHEUR/AGEN.1143944
ArcabitTrojan.Generic.D245B624
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32BScope.Backdoor.SdBot
ALYacTrojan.GenericKD.38123044
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.ACSC!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Win32/Agent.ACSC?

Win32/Agent.ACSC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment