Trojan

Should I remove “Dropped:Trojan.AgentWDCR.ERJ (B)”?

Malware Removal

The Dropped:Trojan.AgentWDCR.ERJ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.AgentWDCR.ERJ (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the FloodFix malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropped:Trojan.AgentWDCR.ERJ (B)?


File Info:

name: A6516E9EB3E1F0200861.mlw
path: /opt/CAPEv2/storage/binaries/6adff2ba6bcf93b3754ebb3670b4f79df073d89a6fb405af79798a8830f891b5
crc32: 22C28058
md5: a6516e9eb3e1f0200861c9211ed03b4b
sha1: 194dbd88c58b6d3cc6fa0209c93a390585282feb
sha256: 6adff2ba6bcf93b3754ebb3670b4f79df073d89a6fb405af79798a8830f891b5
sha512: 72b36c4df20cdfde6b65060ad17104098e9e42b3a58b46e5af32f2cce926b7f35a35a5f92d8220146fa25cac163904cf3aa7c7d13fbb371c802f034393904f2c
ssdeep: 6144:KYEUXL/HkcdeKblntiBvOviaBV+UdvrEFp7hK+t1DN:KYEq/EFcntiBaBjvrEH7znN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11524DF80668483EEF0B60A7031796A5149F5FD3D14BF910ED702BA8D3E7DA43DA98B17
sha3_384: e4641a230c2d1be38e214ece1f87302e511cbc71f28fc2095498476791dc37ba6eba74d41110e09acf9e0a388c1097ef
ep_bytes: e841deffffc33c608bec83c52454e855
timestamp: 2012-02-24 19:19:59

Version Info:

Comments: A build of the PortableApps.com Launcher for HitmanProPortable, allowing it to be run from a removable drive. For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: HitmanProPortable (PortableApps.com Launcher)
FileVersion: 2.2.3.0
InternalName: PortableApps.com Launcher
LegalCopyright: PortableApps.com
LegalTrademarks: PortableApps.com is a Trademark of Rare Ideas, LLC.
OriginalFilename: HitmanProPortable.exe
ProductName: HitmanProPortable
ProductVersion: 2.2.3.0
Translation: 0x0000 0x04e6

Dropped:Trojan.AgentWDCR.ERJ (B) also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Pioneer.lTXd
ElasticWindows.Virus.Floxif
DrWebWin32.FloodFix.7
MicroWorld-eScanDropped:Trojan.AgentWDCR.ERJ
FireEyeGeneric.mg.a6516e9eb3e1f020
CAT-QuickHealW32.Pioneer.CZ1
SkyhighBehavesLike.Win32.Generic.dc
McAfeeDownloader-ASH.gen.g
MalwarebytesFloxif.Virus.FileInfector.DDS
SangforVirus.Win32.Save.Floxif
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderDropped:Trojan.AgentWDCR.ERJ
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.8c58b6
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Floxif.H
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Pioneer-9111434-0
KasperskyVirus.Win32.Pioneer.cz
NANO-AntivirusVirus.Win32.Pioneer.bvrqhu
SophosW32/Floxif-G
F-SecureMalware.W32/Floxif.iici
VIPREDropped:Trojan.AgentWDCR.ERJ
TrendMicroTROJ_GEN.R002C0DK723
Trapminemalicious.moderate.ml.score
EmsisoftDropped:Trojan.AgentWDCR.ERJ (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.eeffo
VaristW32/Floxif.B
AviraW32/Floxif.iici
MAXmalware (ai score=88)
Antiy-AVLVirus/Win32.Floxif
Kingsoftmalware.kb.a.834
MicrosoftVirus:Win32/Floxif.H
XcitiumVirus.Win32.Floxif.A@7h5wha
ArcabitTrojan.AgentWDCR.ERJ
ZoneAlarmVirus.Win32.Pioneer.cz
GDataWin32.Virus.Floxif.A
GoogleDetected
VBA32Virus.Win32.Floxif.h
ALYacDropped:Trojan.AgentWDCR.ERJ
DeepInstinctMALICIOUS
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0DK723
IkarusVirus.Win32.Floxif.A
FortinetW32/Floxif.E
AVGWin32:Pioneer-C
AvastWin32:Pioneer-C
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Dropped:Trojan.AgentWDCR.ERJ (B)?

Dropped:Trojan.AgentWDCR.ERJ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment