Malware

Win32/Agent.WTF removal

Malware Removal

The Win32/Agent.WTF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.WTF virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Win32/Agent.WTF?


File Info:

crc32: DBD87A7C
md5: bdfa523e5a06c417e30f0daecb6215f3
name: BDFA523E5A06C417E30F0DAECB6215F3.mlw
sha1: 4d5b18f90129040a31431b836a8d006e90b47d81
sha256: 1e8441f0d32d3854e0b3801063f6015a9f09637d77b714f8e58fb8c198693a51
sha512: 4a3d7de7e6a0299e66cabd9c9bee94900ae1da557b4870e5b5908abd205b8758f367dacd1e4cea164bb9f4c2a1e4e2cd37ea5477bcec514686bf850340989590
ssdeep: 49152:MfLe1QLqYinLEOz6VaAY0mOmD+MK03LRkpdWGZo09AxnemERApAi4EuWlV1d:MC1PYinTz6Va8QXD3LoA4ohJERAii/L
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Agent.WTF also known as:

BkavW32.AIDetectVM.malware1
DrWebBackDoor.PcClient.6627
CynetMalicious (score: 85)
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.45083921
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1632392
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/PcShare.bc1af3d8
K7GWTrojan ( 00563cb01 )
K7AntiVirusTrojan ( 00563cb01 )
CyrenW32/Trojan.JUJI-7602
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.WTF
AvastOther:Malware-gen [Trj]
KasperskyTrojan.Win32.PcShare.s
BitDefenderTrojan.GenericKD.45083921
MicroWorld-eScanTrojan.GenericKD.45083921
TencentWin32.Trojan.Pcshare.Plaw
Ad-AwareTrojan.GenericKD.45083921
SophosMal/Generic-R + Mal/VMProtBad-A
ComodoMalware@#4puj8zmfvw84
F-SecureTrojan.TR/Agent.letbd
BitDefenderThetaGen:NN.ZedlaF.34742.7R4@aq1Y8Jpi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R02DC0RKJ20
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.bdfa523e5a06c417
EmsisoftTrojan.GenericKD.45083921 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Marai
AviraTR/Agent.letbd
Antiy-AVLTrojan/Win32.PcShare
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA1E
GridinsoftTrojan.Win32.Agent.ns
ArcabitTrojan.Generic.D2AFED11
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmTrojan.Win32.PcShare.s
GDataTrojan.GenericKD.45083921
AhnLab-V3Trojan/Win32.PcClient.R191990
McAfeeArtemis!BDFA523E5A06
MAXmalware (ai score=88)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R02DC0RKJ20
RisingTrojan.Generic@ML.95 (RDMK:B8kJ+bAD4zX34vmPdHktFQ)
YandexTrojan.PcShare!kTPiiRkXQM0
IkarusTrojan.Win32.Agent
FortinetW32/Agent.A!tr
AVGOther:Malware-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.5353.Malware.Gen

How to remove Win32/Agent.WTF?

Win32/Agent.WTF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment