Trojan

Trojan-Dropper.Win32.Agent.tgbcwu removal guide

Malware Removal

The Trojan-Dropper.Win32.Agent.tgbcwu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.tgbcwu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Agent.tgbcwu?


File Info:

name: BA18016979813EF270F1.mlw
path: /opt/CAPEv2/storage/binaries/3e6ee8c9e10138383d310e42d63f974d4101177fb83569fb74eeb84323930913
crc32: F20B0300
md5: ba18016979813ef270f1c8b6cb7c0790
sha1: a9c49553b2b1204eec0d3aae43059a30ca861f9b
sha256: 3e6ee8c9e10138383d310e42d63f974d4101177fb83569fb74eeb84323930913
sha512: 5c39f245befa027f90421a024e3053880d076d8f07eb8a168d80ad30ad34538e0cfa798126c578966e957c608efb4d1110cbfe399373794975b1a25707d9959b
ssdeep: 12288:UT+hbwVXegIAtqw3yGcyA2j/x3nmX8SLJsZPBTaWtKJLZmN1Sa8Y:UTJpegVqWyJ9/8SAPNALZmN1Sa8Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F05F112F6C002B1C1D11A725C6999B2477BED6392E9ED9324C8F7093673D60D339AEE
sha3_384: d9a65765586bcea04845ccd7f5bb0464b68ac2f42deac04231495005424dd4e7c6de84acb5feeffe1e04a15fb75e3df5
ep_bytes: e8ff190000e97ffeffff3b0da0404100
timestamp: 2003-02-27 04:20:07

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Word
FileVersion: 14.0.6024.1000
InternalName: WinWord
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2010
ProductVersion: 14.0.6024.1000
Translation: 0x0000 0x04e4

Trojan-Dropper.Win32.Agent.tgbcwu also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.545749
FireEyeGeneric.mg.ba18016979813ef2
CAT-QuickHealTrojan.GenericRI.S31998617
SkyhighBehavesLike.Win32.Generic.cc
McAfeeGenericRXMT-FC!BA1801697981
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.545749
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 005490181 )
K7AntiVirusTrojan ( 005490181 )
VirITTrojan.Win32.Salgorea.B
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RTY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Agent.tgbcwu
BitDefenderGen:Variant.Zusy.545749
NANO-AntivirusVirus.Win32.Sality.bgiylc
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:DropperX-gen [Drp]
TencentTrojan.Win32.Agent.hct
TACHYONTrojan-Dropper/W32.Agent.840839
EmsisoftGen:Variant.Zusy.545749 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.Fakealert.58572
ZillyaDropper.Agent.Win32.577641
Trapminemalicious.high.ml.score
SophosTroj/Mdrop-JTO
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Generic.hrsto
VaristW32/Agent.ION.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Dropper]/Win32.Facido
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Facido.A!bit
XcitiumTrojWare.Win32.TrojanDropper.Facido.A@7d50kc
ArcabitTrojan.Zusy.D853D5
ZoneAlarmTrojan-Dropper.Win32.Agent.tgbcwu
GDataWin32.Trojan.PSE.1FH43YQ
GoogleDetected
AhnLab-V3Dropper/Win.FC.R641846
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36804.Z03@ay@0URii
ALYacGen:Variant.Zusy.545749
MAXmalware (ai score=81)
VBA32BScope.TrojanDropper.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDropper.Agent!1.B38C (CLASSIC)
YandexTrojan.DR.Agent!5RsQNu/bpqU
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.RTY!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan-Dropper.Win32.Agent.tgbcwu?

Trojan-Dropper.Win32.Agent.tgbcwu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment