Trojan

Trojan-Dropper.Win32.Agent.tgbcvd (file analysis)

Malware Removal

The Trojan-Dropper.Win32.Agent.tgbcvd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.tgbcvd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Agent.tgbcvd?


File Info:

name: 52AE20E1602E630B7488.mlw
path: /opt/CAPEv2/storage/binaries/30f8890022d3004734ae1605098594dfb1e0e00eb2a8c56eab6fcaed078d4f16
crc32: E16EF61C
md5: 52ae20e1602e630b7488c5b559591698
sha1: 2c86524c19fe6b7c0820bbe07b6ad67c4c3bd5f4
sha256: 30f8890022d3004734ae1605098594dfb1e0e00eb2a8c56eab6fcaed078d4f16
sha512: 1e4927bf75f9a7da8195c87b9c276434e8ac2ee996b02fce2d0f5b8b42834c267322231dbccdcdc1d4df07b5c6bed13a51047c893eb26c5ecb3051073cc70fa4
ssdeep: 24576:Uamb1nf9wr6OcOJ/zMH3OfeErLZmN1VUZmSordfqsH:UamdVwmOAH3OmEPZmXiZmSadfqw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A435D002FC8041B0C4DD29364CBA86330BB27D5384D5A94779C8FB663877DD9B725AAE
sha3_384: 9c521d819ae9240fed25eea7fd0704b2de20fd7e1970e2dcdba0d49dd8de6cbc22e4b095e48eefeca0908f102e15fe1a
ep_bytes: e8ff190000e97ffeffff3b0da0404100
timestamp: 2014-02-09 04:20:07

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Word
FileVersion: 14.0.6024.1000
InternalName: WinWord
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2010
ProductVersion: 14.0.6024.1000
Translation: 0x0000 0x04e4

Trojan-Dropper.Win32.Agent.tgbcvd also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.105937
FireEyeGeneric.mg.52ae20e1602e630b
CAT-QuickHealTrojan.GenericRI.S30115126
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXWH-MA!52AE20E1602E
Cylanceunsafe
ZillyaDropper.Agent.Win32.577747
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/Facido.257d400f
K7GWTrojan ( 005490181 )
K7AntiVirusTrojan ( 005490181 )
BitDefenderThetaGen:NN.ZexaF.36802.d93@aq5CMYfi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RTY
APEXMalicious
ClamAVWin.Malware.Facido-9768987-0
KasperskyTrojan-Dropper.Win32.Agent.tgbcvd
BitDefenderTrojan.GenericKDZ.105937
NANO-AntivirusTrojan.Win32.Fakealert.fhnukn
AvastWin32:DropperX-gen [Drp]
TencentTrojan.Win32.Agent.hct
EmsisoftTrojan.GenericKDZ.105937 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen4
DrWebTrojan.Fakealert.58572
VIPRETrojan.GenericKDZ.105937
Trapminemalicious.high.ml.score
SophosTroj/Mdrop-JTO
IkarusTrojan.Win32.Dropper
JiangminTrojan.Generic.hrsto
GoogleDetected
AviraTR/Crypt.ZPACK.Gen4
VaristW32/Agent.ION.gen!Eldorado
Antiy-AVLTrojan[Dropper]/Win32.Facido
MicrosoftTrojanDropper:Win32/Facido.A!bit
XcitiumTrojWare.Win32.TrojanDropper.Facido.A@7d50kc
ArcabitTrojan.Generic.D19DD1
ZoneAlarmTrojan-Dropper.Win32.Agent.tgbcvd
GDataWin32.Trojan.PSE.1M1VZ96
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.MA.R641914
Acronissuspicious
VBA32BScope.TrojanDropper.Agent
ALYacTrojan.GenericKDZ.105937
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingDropper.Agent!1.B38C (CLASSIC)
YandexTrojan.DR.Agent!bJ7T5evHLzQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.12026031.susgen
FortinetW32/Agent.RTY!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Facido.A!bit

How to remove Trojan-Dropper.Win32.Agent.tgbcvd?

Trojan-Dropper.Win32.Agent.tgbcvd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment