Trojan

Trojandropper.Agent.A5 removal

Malware Removal

The Trojandropper.Agent.A5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojandropper.Agent.A5 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings

How to determine Trojandropper.Agent.A5?


File Info:

name: 95F71BD2FA6171EC3E11.mlw
path: /opt/CAPEv2/storage/binaries/1a25bfb9248314d995d04f1f323be2ef3dbe67f50b4a557109c08e694bb6cca0
crc32: 2E55F423
md5: 95f71bd2fa6171ec3e11352445e4dbae
sha1: 15bda3e29f2b8a1c47f83649ae1253bbc4d8fcea
sha256: 1a25bfb9248314d995d04f1f323be2ef3dbe67f50b4a557109c08e694bb6cca0
sha512: d3c927cbfd283d69dd7972666faf50ae3c9a250114ac48be5efaea97dced9a74efede82a6bf75746f709eeaa3b77d95967cbdd5e1833db9084cb90fae509a513
ssdeep: 24576:Ft9EmGXtYzIHoejyRsWasDjU4c//////V:Ft9EmGXtYOOak1c//////V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109052811FEE0847BC875423159F78671B2B2F9567F16CB43A34876383A213A16A172FE
sha3_384: 1bba81acf16522a971507fbdbf8f7d9d8aceca2389ab70892f8e5c56b27a175b83ece6b0df647675f82783a1b5ae3707
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-11-20 20:28:11

Version Info:

Comments:
CompanyName:
FileDescription: Haote.com
FileVersion: 2010-9-20.2
LegalCopyright:
LegalTrademarks:
ProductName:
Translation: 0x0409 0x04e4

Trojandropper.Agent.A5 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NSIS.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Nsis.Agent.Z
FireEyeTrojan.Nsis.Agent.Z
CAT-QuickHealTrojandropper.Agent.A5
SkyhighGenDownloader.oy
McAfeeGenDownloader.oy
MalwarebytesAdware.Kraddare
VIPRETrojan.Nsis.Agent.Z
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0051ad661 )
BitDefenderTrojan.Nsis.Agent.Z
K7GWTrojan ( 0051ad661 )
tehtrisGeneric.Malware
ESET-NOD32Win32/PSW.Agent.NTJ
APEXMalicious
ClamAVWin.Trojan.NSIS-33
KasperskyTrojan-Dropper.Win32.NSIS.tz
AlibabaTrojanDropper:Win32/Dwnldr.a8766e54
NANO-AntivirusTrojan.Win32.Agent.cyombb
RisingTrojan.DL.Agent.ak (CLASSIC)
SophosTroj/Dwnldr-JTN
BaiduWin32.Trojan-Downloader.Agent.ka
F-SecureTrojan.TR/NSIS.13284
DrWebTrojan.MulDrop4.10819
ZillyaDropper.NSIS.Win32.738
EmsisoftTrojan.Nsis.Agent.Z (B)
IkarusTrojan-PSW.Agent
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/NSIS.13284
VaristW32/Agent.FWQ.gen!Eldorado
Antiy-AVLTrojan[Dropper]/Win32.NSIS.tz
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Dynamer!dtc
XcitiumMalware@#r8peg35usvoe
ArcabitTrojan.Nsis.Agent.Z
ZoneAlarmTrojan-Dropper.Win32.NSIS.tz
GDataTrojan.Nsis.Agent.Z
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R29272
ALYacTrojan.Nsis.Agent.Z
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TencentWin32.Trojan-Dropper.Nsis.Vmhl
SentinelOneStatic AI – Malicious PE
FortinetW32/Dloader.EP!tr.NSIS
AVGNSIS:Downloader-HN [Trj]
AvastNSIS:Downloader-HN [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojandropper.Agent.A5?

Trojandropper.Agent.A5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment