Trojan

About “Win32/TrojanDownloader.Agent.GPE” infection

Malware Removal

The Win32/TrojanDownloader.Agent.GPE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.GPE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Agent.GPE?


File Info:

name: BF3BD863BEA3FF8E7634.mlw
path: /opt/CAPEv2/storage/binaries/70c99920763dbefaa6c9dff8bfa7598da916a69ff2b88673b3f844cf8d83be3c
crc32: 38F3031E
md5: bf3bd863bea3ff8e7634275492c1e9eb
sha1: b01c0ce1a1766b3652221a57bac121b2f2d22463
sha256: 70c99920763dbefaa6c9dff8bfa7598da916a69ff2b88673b3f844cf8d83be3c
sha512: 4e98e7b7ed5a3fa47e310fe1c23c2d76c1894f3733ff4c6740b6cd45e76870aa8b6342393561e09ba2ce82f9fe7c9e3cdbe78e43ed94bc7d91a75d63a8e5d9e9
ssdeep: 24576:N4nXubIQGyxbPV0db26Si9+vogz2dbFFv0S6dS/01icZOEOR5QvJe:Nqe3f65+DidXvh6dS/04OOR5QvJe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D475BF3FB268A53EC4AA0B3245B39360997BBB61B81A8C1F57F0090DCF664701F3B655
sha3_384: 40773e74d422ab504936f559471dcb444370ef8b969011999b43f2b61d0081f52373dac2e86769446847213524737c4c
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Native Instruments Guitar Rig 6 Pro 621 STANDALONE VST AAX
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Native Instruments Guitar Rig 6 Pro 621 STANDALONE VST AAX
ProductVersion: 2.0
Translation: 0x0000 0x04b0

Win32/TrojanDownloader.Agent.GPE also known as:

LionicTrojan.Win32.Badur.4!c
MalwarebytesGeneric.Malware/Suspicious
SangforDownloader.Win32.Agent.Vimm
CrowdStrikewin/grayware_confidence_70% (W)
AlibabaTrojanDownloader:Win32/Generic.90436867
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GPE
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:Trojan.Win32.Badur
AvastWin32:Trojan-gen
TencentWin32.Trojan-Downloader.Oader.Iqil
F-SecureTrojan.TR/Dldr.Agent.skkln
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataWin32.Trojan.Agent.XMZ2QO
AviraTR/Dldr.Agent.skkln
ViRobotTrojan.Win.Z.Agent.1604226
ZoneAlarmUDS:Trojan.Win32.Badur
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!BF3BD863BEA3
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CBR23
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.GPE!tr.dldr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Win32/TrojanDownloader.Agent.GPE?

Win32/TrojanDownloader.Agent.GPE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment