Trojan

About “Trojan-Dropper.Win32.Demp.rgc” infection

Malware Removal

The Trojan-Dropper.Win32.Demp.rgc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Demp.rgc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Demp.rgc?


File Info:

name: 780EDF0FBAB486B544E3.mlw
path: /opt/CAPEv2/storage/binaries/fc0c4fb6808c0f8e04361fca62f18d1a72e712e53787e5b8fb9094403ae51f89
crc32: 6E8C3853
md5: 780edf0fbab486b544e3012d187a7920
sha1: 67d4cfef24c9b31e3fd5a7b40ced972b877d97fa
sha256: fc0c4fb6808c0f8e04361fca62f18d1a72e712e53787e5b8fb9094403ae51f89
sha512: 9e6ba653f1f999b1741a947a6aa4cee6d64518015d88ceea0e6396eb58b91b02885a245ec44edc81c742e5c9fa21a6b7b97f6e043bb345a0e0be771dc0854b81
ssdeep: 24576:w584XR/5Pnp5ItYM/ABtAbghHXjRZqtSIU06jNnuK+raA+gVTPlc5/N8Y:z4t9IWtZ3WtSHRuK+rbVGj8Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18335233D74B497A4ED1780308A36967425623C14DE6888D3BA0DB7DF7B787A0733E4A9
sha3_384: 2c02ade3dd6d0ecb22f8493df8d6942294c99eede9acb1122e016038cf6b1e22f9a38577204ade52d367792ea0e4d286
ep_bytes: 558bec83ec4456ff15a04040008bf08a
timestamp: 2011-04-26 16:15:03

Version Info:

CompanyName: LogMeIn, Inc.
FileDescription: LogMeIn Rescue
FileVersion: 6.3.377
InternalName: Rescue
LegalCopyright: Copyright © 2005-2011 LogMeIn, Inc. US patents pending.
OriginalFilename: LMIRescue.exe
ProductName: LogMeIn Rescue
ProductVersion: 6.3.377
Translation: 0x0409 0x04b0

Trojan-Dropper.Win32.Demp.rgc also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
McAfeeGenericRXAA-FA!780EDF0FBAB4
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f24c9b
VirITTrojan.Win32.Siggen3.CFNR
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
KasperskyTrojan-Dropper.Win32.Demp.rgc
NANO-AntivirusTrojan.Win32.Demp.cwgcxh
AvastWin32:Malware-gen
ComodoTrojWare.Win32.TrojanDropper.Daws.AWVZ@7pjjd8
DrWebTrojan.Siggen3.38887
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
JiangminTrojanDropper.Demp.agp
ZoneAlarmTrojan-Dropper.Win32.Demp.rgc
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Dropper/Win.Demp.C5236718
VBA32TrojanDownloader.Agent
MalwarebytesTrojan.Dropper
RisingTrojan.Generic@AI.94 (RDMK:HA5mb5XcYjTy5CIEtPA1Pw)
YandexTrojan.GenAsa!UDf0q+0dCWo
IkarusTrojan-Dropper.Win32.Demp
MaxSecureTrojan.Malware.8599623.susgen
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Dropper.Win32.Demp.rgc?

Trojan-Dropper.Win32.Demp.rgc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment