Trojan

Trojan-Dropper.Win32.Agent.tetrab removal guide

Malware Removal

The Trojan-Dropper.Win32.Agent.tetrab is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.tetrab virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Dropper.Win32.Agent.tetrab?


File Info:

name: B1A467D7C7394E8CDEAF.mlw
path: /opt/CAPEv2/storage/binaries/861348415fd49b8e7ce7850c64ebe66159f48fe81b8296846027884a8224b72d
crc32: 5FEC337E
md5: b1a467d7c7394e8cdeafb0f9993e35bc
sha1: 2fa26fcc5564288384705b3bd6837234ab5e470f
sha256: 861348415fd49b8e7ce7850c64ebe66159f48fe81b8296846027884a8224b72d
sha512: b09b06623e45bb96778fbd230af6a97ef0dacf3e08aadc0510c0f532e0e2c955ff41575176864570e54f63dcc26e0451c3ea7269f4bf4f1867564b7eb8b917c7
ssdeep: 98304:XALCEzFALQTN4dfT71gTzijGqLHA9oHwYX44E8fRYkXVaDCak2ubqLGLOPYnwgyh:QLCEsKyQzijjLfQW4HcYkXVMfnubqiLy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151563342C1F8C1B5D485E674CC2714F6A42A6F19FA3C0CCBAA9E3E4DBE373A155429D2
sha3_384: e0b9382552cc47b00c8711a52161ad9b05969024d1ac931b0f0718c80ac672224284327da2f51a56be906da3b71080ca
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: 3102and2305
FileVersion: 9.6.1.2
LegalCopyright:
ProductName: EZlink-client(WIN7 or WIN10)
ProductVersion: 9.6.1.2
Translation: 0x0000 0x04b0

Trojan-Dropper.Win32.Agent.tetrab also known as:

LionicTrojan.Win32.Agent.b!c
MicroWorld-eScanTrojan.GenericKD.42578376
FireEyeTrojan.GenericKD.42578376
McAfeeArtemis!B1A467D7C739
CylanceUnsafe
SangforTrojan.Win32.Agent.tetrab
AlibabaTrojanDropper:Win32/Dinwod.13c04f93
K7GWTrojan ( 00560fd21 )
K7AntiVirusTrojan ( 00560fd21 )
SymantecTrojan.Gen.2
KasperskyTrojan-Dropper.Win32.Agent.tetrab
BitDefenderTrojan.GenericKD.42578376
NANO-AntivirusTrojan.Win32.RiskGen.cyhdpl
ViRobotTrojan.Win32.Z.Agent.5931025
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.42578376 (B)
DrWebTrojan.MulDrop11.45451
ZillyaTrojan.Foreign.Win32.58095
TrendMicroTROJ_GEN.R002C0WE422
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
IkarusPUA.EmoneyCN
GDataWin32.Application.EmoneyCN.A
JiangminTrojanDropper.Agent.gjln
AviraTR/Downloader.Gen2
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.GenericKD.42578376
VBA32TrojanDropper.Agent
TrendMicro-HouseCallTROJ_GEN.R002H07DP22
RisingTrojan.Generic@AI.88 (RDML:GL24dSt6ycMa/hygrKj+yg)
FortinetW32/Agent.TETRAB!tr
AVGWin32:Malware-gen
Cybereasonmalicious.7c7394
PandaTrj/CI.A

How to remove Trojan-Dropper.Win32.Agent.tetrab?

Trojan-Dropper.Win32.Agent.tetrab removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment