Trojan

TrojanDropper.Agent removal guide

Malware Removal

The TrojanDropper.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What TrojanDropper.Agent virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Slovak
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine TrojanDropper.Agent?


File Info:

crc32: CD0AFEAC
md5: 307c5b34037919495eb43810e867c16a
name: starticon0.exe
sha1: 479ee357e4ea9430df252430a310f92d22e2a0a9
sha256: c84f1d6b8acb9807baf2a16dd480f64b307ade9b57b7a2d387a033e85cf5d83e
sha512: 7c7676e84df3ef63005f1e0b4239456aa000b7f0721310073b89b9abc6347a30a771d45d95c9479f920b332a029e0083a2038efb31eb3d89d15051cea6aff4f2
ssdeep: 12288:08g8kuUqYYpSENjePXhBEK+tHeqcG0vQT8r3ZoVtQBKLKs0kY2XXVVJ:08XkuUcpS0j82jXT8mDq+1XXV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, ghjhfkh
InternalName: fyukfuyk.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0841 0x04c4

TrojanDropper.Agent also known as:

MicroWorld-eScanTrojan.GenericKD.32662699
CAT-QuickHealRansom.Stop.MP4
McAfeeRDN/Generic BackDoor
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32662699
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7e4ea9
Invinceaheuristic
F-ProtW32/Kryptik.ANT.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generickdz-7357865-0
GDataTrojan.GenericKD.32662699
KasperskyTrojan.Win32.Chapak.ebqm
AlibabaTrojan:Win32/Chapak.ccacd75d
AegisLabTrojan.Win32.Bandit.tqTK
AvastFileRepMetagen [Malware]
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32662699 (B)
ComodoMalware@#109srza2n2cvr
F-SecureTrojan.TR/AD.VidarStealer.cauu
DrWebTrojan.PWS.Stealer.27284
ZillyaTrojan.Chapak.Win32.84672
TrendMicroTROJ_FRS.VSNW1FJ19
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeGeneric.mg.307c5b3403791949
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Kryptik.ANT.gen!Eldorado
JiangminAdWare.Generic.jyiy
WebrootW32.Trojan.Gen
AviraTR/AD.VidarStealer.cauu
Antiy-AVLTrojan[Backdoor]/Win32.Predator
ArcabitTrojan.Generic.D1F264AB
ViRobotTrojan.Win32.S.Agent.808448.A
ZoneAlarmTrojan.Win32.Chapak.ebqm
MicrosoftBackdoor:Win32/Predator.J!MTB
AhnLab-V3Trojan/Win32.MalPe.R296515
Acronissuspicious
BitDefenderThetaGen:Trojan.Heur2.PPBB.3.0.XC0@c0oL48kG7d
ALYacTrojan.GenericKD.32662699
MAXmalware (ai score=80)
VBA32TrojanDropper.Agent
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.GXTK
TrendMicro-HouseCallTROJ_FRS.VSNW1FJ19
RisingTrojan.Kryptik!1.BE9F (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.DWPH!tr
Ad-AwareTrojan.GenericKD.32662699
AVGFileRepMetagen [Malware]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.63c

How to remove TrojanDropper.Agent?

TrojanDropper.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment