Trojan

Trojan.RDPGrabber removal tips

Malware Removal

The Trojan.RDPGrabber is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RDPGrabber virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan.RDPGrabber?


File Info:

name: AA65DAA6CEB2AD129A8B.mlw
path: /opt/CAPEv2/storage/binaries/0f2f1136259f527b2482561b51bf4fcf88c323414ec31a5c0f10eceeb6a93340
crc32: 76EA2CE1
md5: aa65daa6ceb2ad129a8b582ea0d824e1
sha1: 481561316b55073cb0000d9a54a22414d60732d1
sha256: 0f2f1136259f527b2482561b51bf4fcf88c323414ec31a5c0f10eceeb6a93340
sha512: 83afbe982bc1d1a3b314615de23fb65e8d6ce2b2883c5f83db82cec3c4960d2b418a6225a489cf016c3ade5adadd222652b1b676893cc97eca151d4c3691c254
ssdeep: 96:sxNlv/rn2JKbqXRh9btaBL4fd/XlxAV579WbhRN6ylfwls+VUNbN+EhkL1aGFyzj:C/rn2JKb+RhKLCxa9WbhRNNWUJyLb0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F202DA06E7F84A25D5FA8B3C58F6431052B6F6936633CE1E2CC500EDAD22B54CA537E5
sha3_384: 16489b565056040c7b772ecbec8814c717e8585844cab25b2fbac3fe4560c43833eeb88e7c0f426441bc12da022b3277
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-06-09 12:11:01

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: rdp.exe
LegalCopyright:
OriginalFilename: rdp.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan.RDPGrabber also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericFC.S30154231
ALYacIL:Trojan.MSILZilla.6980
MalwarebytesTrojan.RDPGrabber
ZillyaTrojan.Agent.Win32.3551410
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderIL:Trojan.MSILZilla.6980
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
CyrenW32/MSIL_Agent.FHD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.EMZ
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Agent.gen
MicroWorld-eScanIL:Trojan.MSILZilla.6980
AvastWin32:SpywareX-gen [Trj]
RisingSpyware.Agent!8.C6 (TFE:dGZlOgxukWmgXBttrQ)
EmsisoftIL:Trojan.MSILZilla.6980 (B)
DrWebTrojan.MulDrop21.36588
VIPREIL:Trojan.MSILZilla.6980
McAfee-GW-EditionBehavesLike.Win32.Downloader.xt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.aa65daa6ceb2ad12
SophosGeneric ML PUA (PUA)
IkarusTrojan.MSIL.Spy
MAXmalware (ai score=82)
Antiy-AVLTrojan[Spy]/MSIL.Agent
MicrosoftTrojan:MSIL/Rzelt.A!MTB
ArcabitIL:Trojan.MSILZilla.D1B44
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan-Spy.Agent.BNB
GoogleDetected
AhnLab-V3Trojan/Win.RealProtect-LS.C5420968
McAfeeGenericRXVW-XW!AA65DAA6CEB2
TACHYONTrojan/W32.DN-Agent.8704.CL
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent_AGen.AZ!tr.spy
BitDefenderThetaGen:NN.ZemsilF.36348.am0@aSOk4Ok
AVGWin32:SpywareX-gen [Trj]
Cybereasonmalicious.16b550
DeepInstinctMALICIOUS

How to remove Trojan.RDPGrabber?

Trojan.RDPGrabber removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment