Trojan

Trojan-Dropper.Win32.Agent.tetthq (file analysis)

Malware Removal

The Trojan-Dropper.Win32.Agent.tetthq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.tetthq virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Attempts to disable Windows Defender

How to determine Trojan-Dropper.Win32.Agent.tetthq?


File Info:

crc32: 7080E1D7
md5: ee8891f4c8317039d811e0862d5d1d3a
name: EE8891F4C8317039D811E0862D5D1D3A.mlw
sha1: 38746e8de494d6f9277786d0f5f202fe6204d8ad
sha256: 94e022e7adcfcef7a6c509b064c591a99743faf8f7e2d1c791212a05f611247f
sha512: 09e62e1a751c57244fd4828f16a5a6ce3712bf349485ef77ad2557b3220c35acf2df7389508b0c74d674ec81d4892251c5016cfc973039f0b3f16ae10f695018
ssdeep: 98304:91OIuO2X1+qx6giGKn0dCEzye096CLx+GOV60LoWfHfeSy/oF8fe9XY6rBUQdhBu:91Oa2fxzi9sLVix32hL3/WNAf99UQNq1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Trojan-Dropper.Win32.Agent.tetthq also known as:

LionicTrojan.Win32.Bingoml.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.47251
CynetMalicious (score: 100)
ALYacGen:Variant.Jaik.48175
CylanceUnsafe
AlibabaAdWare:Win32/Neoreklami.28077536
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.LI
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyTrojan-Dropper.Win32.Agent.tetthq
BitDefenderGen:Variant.Jaik.48175
MicroWorld-eScanGen:Variant.Jaik.48175
Ad-AwareGen:Variant.Jaik.48175
SophosGeneric PUA DI (PUA)
F-SecureHeuristic.HEUR/AGEN.1140578
BitDefenderThetaGen:NN.ZexaF.34266.@JW@aeBa3Vc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.vc
FireEyeGen:Variant.Jaik.48175
EmsisoftGen:Variant.Jaik.48175 (B)
SentinelOneStatic AI – Malicious SFX
AviraHEUR/AGEN.1140578
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Jaik.DBC2F
GDataGen:Variant.Jaik.48175
McAfeeArtemis!EE8891F4C831
MAXmalware (ai score=87)
MalwarebytesAdware.Neoreklami
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CK421
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazq2fo8rziSS9qE+o4076JZa)
FortinetAdware/Neoreklami
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan-Dropper.Win32.Agent.tetthq?

Trojan-Dropper.Win32.Agent.tetthq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment