Trojan

About “Win32/TrojanDownloader.Agent.GCN” infection

Malware Removal

The Win32/TrojanDownloader.Agent.GCN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.GCN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/TrojanDownloader.Agent.GCN?


File Info:

name: FDFD23AA331A3037123D.mlw
path: /opt/CAPEv2/storage/binaries/a20e37c799cdc9bfc8c1052444aa1ecb017b65321ab5e55beb941969cf613122
crc32: 0EFC12AB
md5: fdfd23aa331a3037123dbdb09502ba5c
sha1: 24d25b3db4947a26f01cdb62876feaa4b83a42d0
sha256: a20e37c799cdc9bfc8c1052444aa1ecb017b65321ab5e55beb941969cf613122
sha512: e71296bfd38c25fa68131e4c1903f5553abca5ff46065775f0cbbb589520274751d0a61b39fd7f916eaf946aaf609ee02c00404a9bd59df0fa472be28fd8603a
ssdeep: 192:p7pVmp3cnvbNiW0pIghD6uZN/mMJJ9Vq9dZ:pnlMIghWmtmMhyb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C102090FED964062D1CC0CF017BA45885ABD11233BD920FFBBB2A55A5BD0341949B27E
sha3_384: 64289faa719d8dd1b1a3785a39edc1bf12c9e9bf65d42df7d90987d5c329a7266477225f0abdf66c7deb908e294dbb7a
ep_bytes: e87a040000e936fdffff8bff558bec81
timestamp: 2022-02-03 02:57:43

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.GCN also known as:

LionicTrojan.Win32.Latot.d!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fdfd23aa331a3037
ALYacTrojan.GenericKD.38873473
CylanceUnsafe
SangforInfostealer.Win32.Latot.gen
K7AntiVirusTrojan-Downloader ( 0058defd1 )
AlibabaTrojanDownloader:Win32/Generic.5677f62a
K7GWTrojan-Downloader ( 0058defd1 )
Cybereasonmalicious.db4947
CyrenW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GCN
TrendMicro-HouseCallMal_DLDER
Paloaltogeneric.ml
KasperskyHEUR:Trojan-GameThief.Win32.Latot.gen
BitDefenderTrojan.GenericKD.38873473
MicroWorld-eScanTrojan.GenericKD.38873473
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.38873473 (B)
VIPRETrojan-Downloader.Win32.Small!cobra (v)
TrendMicroMal_DLDER
McAfee-GW-EditionBehavesLike.Win32.Dropper.xm
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Small
AviraTR/Downloader.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-GameThief.Win32.Latot.gen
GDataWin32.Trojan.Agent.UNM9GJ
AhnLab-V3Malware/Win.Dlder.R470415
McAfeeArtemis!FDFD23AA331A
MAXmalware (ai score=86)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesTrojan.Dropper
APEXMalicious
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Mal_DLDER
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/TrojanDownloader.Agent.GCN?

Win32/TrojanDownloader.Agent.GCN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment