Malware

Win32/Agent.ADRX removal guide

Malware Removal

The Win32/Agent.ADRX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ADRX virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Agent.ADRX?


File Info:

name: 1F8CD71469AD04AC8753.mlw
path: /opt/CAPEv2/storage/binaries/fb55ceaf1a66edbba83bdbf34d31ee185c6f4b481fa5ef7e9e8f25cbe3316a3c
crc32: FFDFECE7
md5: 1f8cd71469ad04ac875328fffa6e29f0
sha1: f3db73be878eee2b2f8124381306a61102edd2ec
sha256: fb55ceaf1a66edbba83bdbf34d31ee185c6f4b481fa5ef7e9e8f25cbe3316a3c
sha512: a17699c575f459e33b95350a506b8e81cac3aa92711fe2b977bf86b3b12d426255d3f7c02c6bc8f9a533313756c33d9bf764d4477e5604152f568e65e881cd2b
ssdeep: 1536:eZXAJWXZxqCgo5j9yaf/jYFGDk26l8eEf2ba1ATfIWixCpx8ishXxv5E:eZQIxqhKjf/Z6l8iba18Njmj5E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3A39F51B882F871CA96243004BE9FB28E3C59520FA59ECB47AD1E344F741D1F73A69B
sha3_384: edb18978ddad5b2e92c1f6fed974dfde44368abb2a549fbe8722af327247702bb393dafcca51d6050f17242338bab1b4
ep_bytes: e8d0050000e97afeffff6a0c68a88f06
timestamp: 2021-11-18 18:18:50

Version Info:

0: [No Data]

Win32/Agent.ADRX also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.1f8cd71469ad04ac
McAfeeArtemis!1F8CD71469AD
ZillyaTrojan.Agent.Win32.2564551
SangforTrojan.Win32.Gen.2
CyrenW32/Trojan.PRDT-0488
ESET-NOD32Win32/Agent.ADRX
APEXMalicious
DrWebTrojan.Packed2.43865
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
SophosGeneric PUA PD (PUA)
JiangminExploit.ShellCode.fsy
GridinsoftRansom.Win32.TrickBot.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.Win32.Agent
FortinetW32/TrickBot.CC!tr
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Agent.ADRX?

Win32/Agent.ADRX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment