Trojan

About “Trojan-Dropper.Win32.Agent.tevevx” infection

Malware Removal

The Trojan-Dropper.Win32.Agent.tevevx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.tevevx virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Dropper.Win32.Agent.tevevx?


File Info:

name: 4CE025EE13D9B77FA62B.mlw
path: /opt/CAPEv2/storage/binaries/f23bf2e8d9d514ab288dfe7047f3cecd4f7c6bb72e31b4d9cc16e85aaffc2576
crc32: E62B4AAB
md5: 4ce025ee13d9b77fa62b027fecca3974
sha1: 29690bfbdee851035df6ee54e66521a28d7096da
sha256: f23bf2e8d9d514ab288dfe7047f3cecd4f7c6bb72e31b4d9cc16e85aaffc2576
sha512: 0c4ee080e40c2729459070e55a62eee3e7ff7a7c98eace998ff4ae8f04e00334ef6d73c522d093d5bd0653c7f71d861bea9bcd9eba9062b08b58569d7e8812df
ssdeep: 12288:HU5rCOTeiJHF+/P6H4rlKcsNbm95VMF9PHnaNZ:HUQOJJl+geTsE5i/HaN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197B4F024B145C032F5A211314EE2EBB1693ABD358B26A4C77B90777E6EB02E1E774347
sha3_384: 25f507c65bf35657daddda9bf098b98fd8d54126c9776544cda6e9eddd7b6626b0417de9937c5f029ae57378e1bec554
ep_bytes: e90cec05000000000000000000000000
timestamp: 2003-11-11 14:39:16

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Trojan-Dropper.Win32.Agent.tevevx also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.61639
MicroWorld-eScanTrojan.GenericKDZ.95989
CAT-QuickHealTrojan.GenericRI.S28930490
McAfeeGenericRXHF-BX!4CE025EE13D9
MalwarebytesAgent.Trojan.Dropper.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0043c2cb1 )
K7GWTrojan ( 0043c2cb1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D176F5
BitDefenderThetaGen:NN.ZexaF.36196.Ey0@aasXdhbi
CyrenW32/Upatre.OL.gen!Eldorado
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QGO
APEXMalicious
ClamAVWin.Trojan.Cuegoe-6336261-0
KasperskyTrojan-Dropper.Win32.Agent.tevevx
BitDefenderTrojan.GenericKDZ.95989
NANO-AntivirusVirus.Win32.Gen.ccmw
EmsisoftTrojan.GenericKDZ.95989 (B)
F-SecureHeuristic.HEUR/AGEN.1315087
BaiduWin32.Trojan-Dropper.Agent.ab
VIPRETrojan.GenericKDZ.95989
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4ce025ee13d9b77f
SophosTroj/Salgorea-D
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.gqlz
GoogleDetected
AviraHEUR/AGEN.1315087
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.AGeneric
XcitiumApplication.Win32.Amonetize.NE@5te978
MicrosoftTrojan:Win32/Salgorea.A!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmTrojan-Dropper.Win32.Agent.tevevx
GDataWin32.Trojan.PSE.168GMQ4
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R513806
Acronissuspicious
ALYacTrojan.GenericKDZ.95989
TACHYONTrojan-Dropper/W32.Agent.499200.L
DeepInstinctMALICIOUS
VBA32TrojanDownloader.Upatre
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallPAK_Xed-21
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.DR.Agent!CafrEvhDur4
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Upatre.0285!tr
AVGWin32:Agent-AYZG [Cryp]
Cybereasonmalicious.e13d9b
AvastWin32:Agent-AYZG [Cryp]

How to remove Trojan-Dropper.Win32.Agent.tevevx?

Trojan-Dropper.Win32.Agent.tevevx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment