Rootkit

Win64/Rootkit.Agent.AC (file analysis)

Malware Removal

The Win64/Rootkit.Agent.AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Rootkit.Agent.AC virus can do?

  • Network activity detected but not expressed in API logs

How to determine Win64/Rootkit.Agent.AC?


File Info:

crc32: 431F0698
md5: 787b12d6e493b926124194fd30751886
name: 787B12D6E493B926124194FD30751886.mlw
sha1: aa4b13b04feee4d0f84b8d7332ffcb70d1bab6dd
sha256: 5a08517bbe96511b0ffe6eb7d279dc4332240130714c678178a4bf581e958ba9
sha512: b6f65c03f5497cdf1bbbf7ba837e497d91997c90dc060f11d3cec2199e045981f0a59b5aa2a240de86de30f2da834c17a30602fc833311728991af7e23725665
ssdeep: 768:fFpuhM4dPG0U6X1spQIzbm2wrR2NPfzHcwjdz9rDiA:r2dPGOyp7buITHdZgA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: ANTIBAN.exe
FileVersion: 1.0.0.0
CompanyName: ANTIBAN
LegalTrademarks:
Comments: ANTIBAN
ProductName: ANTIBAN
ProductVersion: 1.0.0.0
FileDescription: ANTIBAN
OriginalFilename: ANTIBAN.exe

Win64/Rootkit.Agent.AC also known as:

K7AntiVirusRootKit ( 005407241 )
LionicTrojan.Win64.Agent.5!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.MSILHeracles.20805
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRootkit:Win64/HacktoolX.488313b7
K7GWRootKit ( 005407241 )
Cybereasonmalicious.04feee
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Rootkit.Agent.AC
APEXMalicious
AvastWin64:HacktoolX-gen [Trj]
KasperskyRootkit.Win64.Agent.bhf
BitDefenderGen:Variant.MSILHeracles.20805
MicroWorld-eScanGen:Variant.MSILHeracles.20805
TencentMsil.Trojan.Msilheracles.Aiil
Ad-AwareGen:Variant.MSILHeracles.20805
SophosMal/Generic-S
McAfee-GW-EditionArtemis!PUP
FireEyeGen:Variant.MSILHeracles.20805
EmsisoftGen:Variant.MSILHeracles.20805 (B)
SentinelOneStatic AI – Malicious PE
JiangminRootkit.Agent.sqj
AviraHEUR/AGEN.1145371
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.MSILHeracles.20805
AhnLab-V3Malware/Win.Generic.C4632312
McAfeeArtemis!787B12D6E493
MAXmalware (ai score=80)
MalwarebytesMalware.AI.259776531
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CKI21
RisingTrojan.MalCert!1.BDE5 (CLASSIC)
IkarusTrojan.Win64.Rootkit
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/Rootkit_Agent.AC!tr
AVGWin64:HacktoolX-gen [Trj]

How to remove Win64/Rootkit.Agent.AC?

Win64/Rootkit.Agent.AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment