Malware

Win32/Agent.ACWL (file analysis)

Malware Removal

The Win32/Agent.ACWL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ACWL virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Agent.ACWL?


File Info:

crc32: 4FC0DA99
md5: 97d350ad089bf731ca70fb5dc5e323fb
name: 97D350AD089BF731CA70FB5DC5E323FB.mlw
sha1: 2ae2cfa3c33cf7be8104205e086e13e167461a01
sha256: 9f997c93b12d68983ffe3d25f39653fd01ea1b81100a52ef2cfedca97f743820
sha512: f1ccc3f53f02ac7ebb8bdecf66decc19335b1c7000d5f55061507ed8e584ea49b0b0d092fd7291f6072dc1f7df96546fd829c32d07d3dbff5a45375114e15318
ssdeep: 3072:i7z0pBJ0e0iDeexMVTdeR3uvsXi5RZScqqAg0FuD0jmXwUD:00HJ0jiwddw3uvsoUqAOsUD
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Agent.ACWL also known as:

K7AntiVirusTrojan ( 00579aec1 )
LionicTrojan.Win32.Mikey.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.WacatacRI.S19475132
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1893093
SangforTrojan.Win32.Glupteba.ml
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/MalwareX.f89d341c
K7GWTrojan ( 00579aec1 )
Cybereasonmalicious.d089bf
CyrenW32/Agent.CPG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACWL
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
NANO-AntivirusTrojan.Win32.Fugrafa.itkkja
TencentMalware.Win32.Gencirc.10cf075e
BitDefenderThetaGen:NN.ZexaF.34266.luW@aGMLQtli
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1142223
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.320ED1C
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1UPWN15
McAfeeGenericRXAA-FA!97D350AD089B
VBA32TrojanPSW.WinCred
MalwarebytesMalware.AI.3260149611
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.82 (RDML:sGPdxRvNUZoFJtPuZ/jF4A)
YandexTrojan.Agent!LmOaqrcU3RU
IkarusTrojan.Win32.Agent
FortinetW32/AGEN.1140488!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Agent.ACWL?

Win32/Agent.ACWL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment