Trojan

How to remove “Trojan-Dropper.Win32.Agent.oxpb”?

Malware Removal

The Trojan-Dropper.Win32.Agent.oxpb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.oxpb virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Agent.oxpb?


File Info:

name: B353FB30262084B263B2.mlw
path: /opt/CAPEv2/storage/binaries/0029311a20279d0a03ab2c9a0c58b416288d3d1fe8005421360fc0b9995cf6bd
crc32: D9858BB9
md5: b353fb30262084b263b2001f92929e01
sha1: f20d59b1f426c92151d34eee1c857bdeb1d5b586
sha256: 0029311a20279d0a03ab2c9a0c58b416288d3d1fe8005421360fc0b9995cf6bd
sha512: 37023a1a5467087d602927332656189c0e97a55711254da56bc4422e98a92d43a05dde25c10a37174d72ab4c99cc47cb154e82ccd3dde2608107487b91c5dc25
ssdeep: 24576:mkaSWwH6N+9IYkvdStJZupoZ2X1F6kTigVoATQckoxxTJNURRRuvCMtVdUhZuIBB:mwd6NCI/cSl76k2kwRrMjd6uIcc8Az
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8851212F293D071C46600B905659BB54F79AD3087B9C4E7AFE13D6EAE313D0AA3734A
sha3_384: bd92e36e0620295b277fc7d320c107bc6f069f4911e3c4ea8b7577dcb2bc6b1f7988e4b3f148b9146adc457a0e476a25
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2014-09-03 15:08:50

Version Info:

Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.3.2.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2014 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFilename: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.3.2.0
Translation: 0x0409 0x04e4

Trojan-Dropper.Win32.Agent.oxpb also known as:

MicroWorld-eScanTrojan.GenericKD.45268208
ALYacTrojan.GenericKD.45268208
CylanceUnsafe
VIPRETrojan.GenericKD.45268208
SangforTrojan.Win32.Agent.8
AlibabaTrojanDropper:Win32/Generic.fc7eaf6d
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Agent.oxpb
BitDefenderTrojan.GenericKD.45268208
AvastFileRepMalware [Trj]
Ad-AwareTrojan.GenericKD.45268208
TrendMicroTROJ_GEN.R002C0WDS22
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminesuspicious.low.ml.score
FireEyeTrojan.GenericKD.45268208
SophosGeneric PUA PC (PUA)
GDataTrojan.GenericKD.45268208
WebrootW32.Agent.Ovxn
AviraTR/Agent.1839148
MAXmalware (ai score=98)
KingsoftWin32.Troj.Agent.ox.(kcloud)
ZoneAlarmTrojan-Dropper.Win32.Agent.oxpb
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!B353FB302620
VBA32BScope.Trojan.FakeAV
MalwarebytesAdware.IndiLoadz
TrendMicro-HouseCallTROJ_GEN.R002C0WDS22
RisingDropper.Agent!8.2F (CLOUD)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.165414011.susgen
FortinetW32/Agent.OXPB!tr
AVGFileRepMalware [Trj]
PandaTrj/CI.A

How to remove Trojan-Dropper.Win32.Agent.oxpb?

Trojan-Dropper.Win32.Agent.oxpb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment