Trojan

What is “TrojanDropper:Win32/Salgorea.AI!MTB”?

Malware Removal

The TrojanDropper:Win32/Salgorea.AI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Salgorea.AI!MTB virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDropper:Win32/Salgorea.AI!MTB?


File Info:

name: 7B3643C3ADCF1170C9AE.mlw
path: /opt/CAPEv2/storage/binaries/284bbe0d2a88ef723a660a22bfc0865ad513c57de6833a82d72e1fa7542c7b01
crc32: 7E4FFA86
md5: 7b3643c3adcf1170c9aea34afa6e8594
sha1: 6f166237a63d7ac7b2d973388ee9378391b3416a
sha256: 284bbe0d2a88ef723a660a22bfc0865ad513c57de6833a82d72e1fa7542c7b01
sha512: d4786d0e7e234581058e41857290a1e03837d26345d59be3adf2860e7a56ea7e3057b600a5ebbd27bff6649452f005b42412684b58d433701f3b3cbd99087794
ssdeep: 6144:98Xyq4o4aRCTuuqepiq+zQ1mBYBqHfMtqeG8xltdhcrIpmEUCi4IXD2jh0/LuxuI:9W4ufepiqKQ1mpHf0esPiHTSQhJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB94E0213692C03AE1A306348BE5DBA5563A7DA54B31A4C73BC43BAF6E741D1DB3434B
sha3_384: 2b6340f6b0694cf5eaeec64566ed97e43d3ba440a066198971f6eb83a0e5a235219cd319a8b49422b9b9beccc534bbcc
ep_bytes: e8585f0000e989feffff8bff558bec5d
timestamp: 2009-03-28 06:09:52

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 11.0.5604
InternalName: WinWord
LegalCopyright: Copyright © 1983-2003 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2003
ProductVersion: 11.0.5604
Translation: 0x0000 0x04e4

TrojanDropper:Win32/Salgorea.AI!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.touv
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.535956
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.gc
McAfeeGenericRXGZ-QS!7B3643C3ADCF
MalwarebytesWapomi.Virus.FileInfector.DDS
ZillyaDropper.Agent.Win32.571457
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Cuegoe.1008
K7GWTrojan ( 005712881 )
K7AntiVirusTrojan ( 005712881 )
ArcabitTrojan.Zusy.D82D94
BaiduWin32.Trojan-Dropper.Agent.z
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QGO
APEXMalicious
TrendMicro-HouseCallTROJ_CUEGOE.SM
ClamAVWin.Trojan.Cuegoe-6336261-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.535956
NANO-AntivirusTrojan.Win32.Agent.bxpjdf
AvastWin32:Agent-ARGM [Rtk]
TencentTrojan.Win32.Agent.xe
EmsisoftGen:Variant.Zusy.535956 (B)
GoogleDetected
F-SecureBackdoor.BDS/Rogue.7735211
DrWebTrojan.MulDrop19.57448
VIPREGen:Variant.Zusy.535956
TrendMicroTROJ_CUEGOE.SM
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7b3643c3adcf1170
SophosTroj/Agent-BIRD
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDropper.Agent.bpmi
WebrootW32.Trojan.Gen
VaristW32/RopProof.H.gen!Eldorado
AviraBDS/Rogue.7735211
Antiy-AVLVirus/Win32.Expiro.ropf
Kingsoftmalware.kb.a.1000
XcitiumApplication.Win32.Amonetize.NE@5te978
MicrosoftTrojanDropper:Win32/Salgorea.AI!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.17PLPXL
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4262763
Acronissuspicious
VBA32BScope.Backdoor.Salgorea
ALYacGen:Variant.Zusy.535956
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.GenAsa!u3VannXTJD4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Upatre.0285!tr
BitDefenderThetaAI:Packer.004469B01F
AVGWin32:Agent-ARGM [Rtk]
Cybereasonmalicious.3adcf1
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Upatre

How to remove TrojanDropper:Win32/Salgorea.AI!MTB?

TrojanDropper:Win32/Salgorea.AI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment