Malware

About “Win32:Agent-ATCX [Trj]” infection

Malware Removal

The Win32:Agent-ATCX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Agent-ATCX [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Win32:Agent-ATCX [Trj]?


File Info:

name: F65D82ABD3D623546362.mlw
path: /opt/CAPEv2/storage/binaries/54cffd74fc8b1877496dd62a6759ba5af2b5c9336993c7799c01aa8d25c55971
crc32: 5E734011
md5: f65d82abd3d623546362595e73f8666d
sha1: 0bc780d6739560299a2b75a4233118ef0e7609eb
sha256: 54cffd74fc8b1877496dd62a6759ba5af2b5c9336993c7799c01aa8d25c55971
sha512: 336fd99198c6eb9deb7bf1c8349aa23b1f2e1554405060f28e82f54369eec936923702dd5bc151f415c3ed437a0dc96323708cf5f53d6c3fc999ca07fe62d2f0
ssdeep: 3072:WMQ5gy3ePyquZ1oTy2kWLAYIaJFZcnkBcnXsgZDn3TG00bR6T0nCB9T0P42HYNkE:WMAg0e2oP6mJFZIkBmZ/K9A21AmQfg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F64F11B0698BCD5E5CD4E316D23C01E2DC76DA81C33993671DA279937F92A082ABE47
sha3_384: 3be08f94346fc7941077654fc08a400c48dbe8156e61ad6315941bb1fa449edc78dc31667100d74b86a83db610a1308b
ep_bytes: 682c144000e8eeffffff000000000000
timestamp: 2014-03-21 15:11:49

Version Info:

Translation: 0x0404 0x04b0
Comments: Mantello Di sabbia
CompanyName: Telerik
FileDescription: Kümmre
LegalCopyright: Arbeiterreservoire4
LegalTrademarks: Frequenztoleranzen1
ProductName: Magnetfeldröhre
FileVersion: 4.08.0001
ProductVersion: 4.08.0001
InternalName: 3
OriginalFilename: 3.exe

Win32:Agent-ATCX [Trj] also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.tm0@de1J7rjb
ClamAVWin.Dropper.Cerber-9814847-0
FireEyeGeneric.mg.f65d82abd3d62354
CAT-QuickHealVirTool.VBInject.LE3
McAfeeGenericATG-FSK!F65D82ABD3D6
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.156319
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004e606d1 )
K7GWTrojan ( 004e606d1 )
Cybereasonmalicious.bd3d62
VirITTrojan.Win32.Generic.AGOX
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.rvyb
BitDefenderGen:Heur.PonyStealer.tm0@de1J7rjb
NANO-AntivirusTrojan.Win32.Zbot.cvyesd
SUPERAntiSpywareTrojan.Agent/Gen-Gamarue
AvastWin32:Agent-ATCX [Trj]
Ad-AwareGen:Heur.PonyStealer.tm0@de1J7rjb
EmsisoftGen:Heur.PonyStealer.tm0@de1J7rjb (B)
ComodoMalware@#3te8nn1zsuv8k
DrWebTrojan.PWS.Panda.2401
VIPREGen:Heur.PonyStealer.tm0@de1J7rjb
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Zbot.emsm
AviraHEUR/AGEN.1206726
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftVirTool:Win32/VBInject.gen!LN
GDataGen:Heur.PonyStealer.tm0@de1J7rjb
GoogleDetected
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
Acronissuspicious
VBA32TrojanSpy.Zbot
ALYacGen:Heur.PonyStealer.tm0@de1J7rjb
MAXmalware (ai score=85)
MalwarebytesTrojan.Zbot.EDFV
RisingMalware.Undefined!8.C (TFE:3:vTTHnC0NUXL)
YandexTrojanSpy.Zbot!ghWdAnoXRno
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.VBB!tr
BitDefenderThetaGen:NN.ZevbaF.34698.tm0@ae1J7rjb
AVGWin32:Agent-ATCX [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:Agent-ATCX [Trj]?

Win32:Agent-ATCX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment