Trojan

About “Win32/TrojanDropper.Agent.RKO” infection

Malware Removal

The Win32/TrojanDropper.Agent.RKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.RKO virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/TrojanDropper.Agent.RKO?


File Info:

name: CE2A0569643DA24D2DD1.mlw
path: /opt/CAPEv2/storage/binaries/3528d2f6e59001f8bde2732ac2b1cfe0c106e67fc101224fcb119bada8cda466
crc32: A1395DEB
md5: ce2a0569643da24d2dd16f3d4cc455b7
sha1: 0b966856b5525ed091ded34c4e9805f976c2308b
sha256: 3528d2f6e59001f8bde2732ac2b1cfe0c106e67fc101224fcb119bada8cda466
sha512: 732ae75d9d2445a4230778cbeedb50929481d9dfc040396d836c5603f652a7eb853509469c2c34ec643cc5c2f608d682abd2ce4bc26e2e35679441f5879d3427
ssdeep: 49152:oeC7es0RTvqz9lcKniN/elU7/6CNYooxaFaCVHSkb:47kK9lc4i58U73BoxCVHSkb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F295120AEA9193F2D81001F86A588FF76D663D391742DEC337D61A4E2D211CAA773B17
sha3_384: 91b14ef25c48fbdcdf40ea7475ca2b05c8fc3f460fc78dedc9e8ea0a58059f69c22d410c0559b95b8d2b8fdf7b88afc7
ep_bytes: e8793e0000e97ffeffff3b0d90dd5b00
timestamp: 2010-02-13 04:28:16

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 4.1.0
ProductVersion: 4.1.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2011
OriginalFilename: WinRAR.exe
Translation: 0x0000 0x0000

Win32/TrojanDropper.Agent.RKO also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mikey.113610
CAT-QuickHealTrojan.Skeeyah.S12845
SkyhighBehavesLike.Win32.Generic.tc
McAfeeDropper-FRS!CE2A0569643D
Cylanceunsafe
VIPREGen:Variant.Mikey.113610
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004e16831 )
K7AntiVirusTrojan ( 004e16831 )
ArcabitTrojan.Mikey.D1BBCA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RKO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Bskd-9753126-0
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Mikey.113610
NANO-AntivirusTrojan.Win32.Mlw.icebmt
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Evo-gen [Trj]
TencentTrojan-Dropper.Win32.Agent.xa
TACHYONTrojan/W32.Salgorea.1908557
EmsisoftGen:Variant.Mikey.113610 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen4
DrWebTrojan.MulDrop7.62214
ZillyaDropper.Agent.Win32.439274
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ce2a0569643da24d
SophosML/PE-A
IkarusTrojan.Win32.Salgorea
JiangminBackdoor.Generic.biag
VaristW32/Trojan.GCD.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen4
Antiy-AVLTrojan[Dropper]/Win32.Agent
Kingsoftmalware.kb.a.965
XcitiumTrojWare.Win32.Salgorea.RPR@7tcxjx
MicrosoftTrojan:Win32/Remcos.AUT!MTB
ZoneAlarmVHO:Backdoor.Win32.Salgorea.gen
GDataWin32.Trojan.PSE.1ESMMVW
GoogleDetected
AhnLab-V3Trojan/Win.Agent.R420146
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.013@a4FDI3gi
ALYacGen:Variant.Mikey.113610
MAXmalware (ai score=84)
VBA32Trojan.MulDrop
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingDropper.Agent!1.B012 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.BJRQPG!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.6b5525
DeepInstinctMALICIOUS

How to remove Win32/TrojanDropper.Agent.RKO?

Win32/TrojanDropper.Agent.RKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment