Malware

Should I remove “Downloader.Win32.Agent.ltdk”?

Malware Removal

The Downloader.Win32.Agent.ltdk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.ltdk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Downloader.Win32.Agent.ltdk?


File Info:

name: A17B3723A6AE1184C59D.mlw
path: /opt/CAPEv2/storage/binaries/6eca7f2fb8c0bc80eec44e8bbab63ec3b4ccc10ee455edf3f7ff86d13a87252d
crc32: 13C88D4D
md5: a17b3723a6ae1184c59d85d42dea2751
sha1: c4f8f4f2f1bb79a15198a2bc367057d5e5b89e2c
sha256: 6eca7f2fb8c0bc80eec44e8bbab63ec3b4ccc10ee455edf3f7ff86d13a87252d
sha512: 8110c3819ed96c4ccb7491c52359536c12c1a97cf06016b3e1f389e4eaf48840d4f507fee62a92c0ff941cc54d28c3f7918b818c0d5a3524479ec12ee522f42a
ssdeep: 12288:1l2D2hO/z0NQca4pEl5GSi769v7vR53MH2X+9:1l26Oz2JzK77i70v7vR53MH79
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131F49D42F58240F5D655183095E67775FB3ABE060F09CA83DB98FE2C5E332819D362BA
sha3_384: 76c89fa62ae89c2559e38fcb3dbb64f9765d963a608b22404d16c64679dc77c416963101e0caeaf88a887a39cf41f751
ep_bytes: 558bec6aff6828c64800683456460064
timestamp: 2018-10-25 03:26:05

Version Info:

FileVersion: 1.0.0.0
FileDescription: 自动更新程序
ProductName: 自动更新程序
ProductVersion: 1.0.0.0
CompanyName: 自动更新程序
LegalCopyright: 自动更新程序 版权所有
Comments: 自动更新程序
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.ltdk also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lpDo
Elasticmalicious (high confidence)
FireEyeGeneric.mg.a17b3723a6ae1184
CylanceUnsafe
SangforPUP.Win32.Agent.ltdk
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Occamy.7d1963cb
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.2f1bb7
BitDefenderThetaGen:NN.ZexaF.34114.Vq0@amF1NXpb
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0DKT21
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.Agent.ltdk
NANO-AntivirusTrojan.Win32.ChinDowl.hcbhgo
AvastWin32:Malware-gen
SophosGeneric PUA ME (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DKT21
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
IkarusTrojan.Win32.Disabler
GDataWin32.Trojan.PSE.183RH9S
JiangminDownloader.ChinDowl.aa
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASMalwS.29070EA
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2839870
McAfeeGenericRXAA-AA!A17B3723A6AE
MAXmalware (ai score=100)
VBA32Downloader.ChinDowl
MalwarebytesTrojan.MalPack.FlyStudio
APEXMalicious
RisingTrojan.Generic@ML.95 (RDML:61ZcS9e6X5DlpO1wraiduw)
YandexTrojan.GenAsa!mLFi6V2e11s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.9064818.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Downloader.Win32.Agent.ltdk?

Downloader.Win32.Agent.ltdk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment