Trojan

Trojan.Win32.SelfDel.argr removal tips

Malware Removal

The Trojan.Win32.SelfDel.argr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.SelfDel.argr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings

How to determine Trojan.Win32.SelfDel.argr?


File Info:

name: FE60F3E21257CE5653B3.mlw
path: /opt/CAPEv2/storage/binaries/736d7092e2cca2a5444a2d244da141427d1f7006bd84d8c28a4adb74f8212482
crc32: C456141E
md5: fe60f3e21257ce5653b39a37829b4cb6
sha1: 15eacdcbc95777fe460ab4d85c2171f98130e5cd
sha256: 736d7092e2cca2a5444a2d244da141427d1f7006bd84d8c28a4adb74f8212482
sha512: 8a6c89e638f9c0b9ec02d2a48ead3aa522009d65964211fbdfa17f426de6a001533084134cf9826d96cc70aa52a264cfded76b4cee36106dad58d36b061e12df
ssdeep: 384:Y9Icz3kBWTHdGav99999999yi9wKKCMfxrZYkdzYHQ+GBgqP9:YRDzv99999999yiuKKCMfxrZY2+Gmg9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AE2B85099E264B8E5BEC2B355F3CD962383BE6031101B2F3899716516332C779FAD2B
sha3_384: fdcca88a160635b4056f35be062143b7f04f01091290bfe744804e6e823b6207d442a7f0089bcd868deabd2aa22ce5a4
ep_bytes: 5589e583ec38c7051030400000004000
timestamp: 2013-10-18 12:32:47

Version Info:

Comments:
CompanyName: IntelCorp
FileDescrsiption: app.exe
FileVersion: 1.0.0.1
InternalName: app.exe
LegalCopyright: Copyright (C) 2002
LegalTrademarks:
OriginalFilename: app.exe
PrivateBuild:
ProductName: App
ProductVersion: 1.0.0.1
SpecialBuild:
Translation: 0x0800 0x0025

Trojan.Win32.SelfDel.argr also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1349673
ClamAVWin.Downloader.Upatre-5744087-0
CAT-QuickHealTrojanDownloader.Upatre.A6
McAfeeDownloader-FUP!FE60F3E21257
CylanceUnsafe
ZillyaTrojan.SelfDel.Win32.17803
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
K7GWTrojan-Downloader ( 0055c6c71 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Downloader.Small.ck
VirITTrojan.Win32.Zbot.CVG
CyrenW32/Trojan.CHSH-5484
SymantecTrojan.Zbot!gen71
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.SelfDel.argr
BitDefenderTrojan.GenericKD.1349673
NANO-AntivirusTrojan.Win32.SelfDel.cjbnkr
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b3846d
Ad-AwareTrojan.GenericKD.1349673
EmsisoftTrojan.GenericKD.1349673 (B)
ComodoTrojWare.Win32.Upatre.B@53h3br
DrWebTrojan.DownLoad3.28161
VIPRETrojan.GenericKD.1349673
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionDownloader-FUP!FE60F3E21257
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fe60f3e21257ce56
SophosML/PE-A + Troj/Agent-AEHP
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.1349673
JiangminTrojan/Selfdel.arrl
AviraTR/Yarwi.B.2
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASBOL.C6E4
ArcabitTrojan.Generic.D149829
MicrosoftTrojanDownloader:Win32/Upatre.A
GoogleDetected
AhnLab-V3Trojan/Win32.SelfDel.R85314
VBA32TrojanDropper.Agent
ALYacTrojan.GenericKD.1349673
MalwarebytesUpatre.Trojan.Downloader.DDS
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Upatre!8.B5 (TFE:1:8cv9jMkJIwG)
YandexTrojan.GenAsa!a1XRvk9KP9s
IkarusTrojan-PWS.Win32.Fareit
MaxSecureTrojan.Upatre.Gen
FortinetW32/Small.AABC!tr
BitDefenderThetaGen:NN.ZexaF.34726.bu1@ai@eRnf
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.21257c
PandaTrj/Downloader.WKY

How to remove Trojan.Win32.SelfDel.argr?

Trojan.Win32.SelfDel.argr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment