Trojan

Trojan-Dropper.Win32.Agent.tetuio removal tips

Malware Removal

The Trojan-Dropper.Win32.Agent.tetuio is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.tetuio virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Dropper.Win32.Agent.tetuio?


File Info:

name: 81C58AA488937DDA6B0D.mlw
path: /opt/CAPEv2/storage/binaries/a2ddc2a3bfd205ba2777b96448fdb488cca1cfee50f2064ed93246810b4c4750
crc32: D6F869D9
md5: 81c58aa488937dda6b0de4264097c0d8
sha1: 5bf5a1d3a402a508bd743c10a85c4dd43825d697
sha256: a2ddc2a3bfd205ba2777b96448fdb488cca1cfee50f2064ed93246810b4c4750
sha512: e31e40c59185d6ad5f96324e0de3f88612d5c65dd8f9166f5cffd78a1a98c075cebbae8515311bf3484e1fc668c2b95c85b3ede8a9dc175403def907bfb71b77
ssdeep: 98304:SaPxgA03vLUkTNDcn2BlJPD8Nzl2UT8mRaw8GFvuztrccwwe0WQSAPx2r:7xg13jUkTNnt8NaLwJ+If/QS2U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D65633AD276C8A1BFBA43C74B5732EA19F70BC53AC3546DE2AD1395C19723967800B34
sha3_384: 4456a1ea69e0a77f8fea5ae1ac35e46069ac3a55f5c9a21a365901d7f1b7e45839c07161774aab7177631341cd8c08c8
ep_bytes: 60be00c0a4008dbe00509bff57eb0b90
timestamp: 2019-10-09 00:49:58

Version Info:

FileVersion: 6.1.19.1009
LegalCopyright: Copyright © 2013-2015
ProductVersion: 6.1.19.1009
授权方式: arFi
Translation: 0x0804 0x04b0

Trojan-Dropper.Win32.Agent.tetuio also known as:

LionicTrojan.Win32.Agent.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.32870993
FireEyeGeneric.mg.81c58aa488937dda
ALYacTrojan.GenericKD.32870993
CylanceUnsafe
SangforSuspicious.Win32.HSTR.AutoitItV3ModGUIDMark
K7AntiVirusTrojan ( 700000111 )
AlibabaPacked:Win32/Generic.84ce6e25
K7GWTrojan ( 700000111 )
Cybereasonmalicious.488937
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Autoit.Y suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CJR21
AvastWin32:Trojan-gen
KasperskyTrojan-Dropper.Win32.Agent.tetuio
BitDefenderTrojan.GenericKD.32870993
TencentWin32.Trojan-dropper.Agent.Eand
Ad-AwareTrojan.GenericKD.32870993
EmsisoftTrojan.GenericKD.32870993 (B)
ZillyaDropper.Agent.Win32.467276
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vc
SophosGeneric PUA FL (PUA)
Paloaltogeneric.ml
GDataWin32.Trojan.BSE.1IAHVXG
AviraHEUR/AGEN.1135820
Antiy-AVLTrojan/Generic.ASCommon.1B8
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!81C58AA48893
MAXmalware (ai score=81)
VBA32TrojanDropper.Agent
MalwarebytesMalware.AI.2616510892
APEXMalicious
RisingTrojan.Obfus/Autoit!1.C72A (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan-Dropper.Win32.Agent.tetuio?

Trojan-Dropper.Win32.Agent.tetuio removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment