Trojan

Win32/TrojanDropper.Agent.RYA removal

Malware Removal

The Win32/TrojanDropper.Agent.RYA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.RYA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/TrojanDropper.Agent.RYA?


File Info:

crc32: 51731196
md5: d816d0c95e63322e6bec26578e45b736
name: D816D0C95E63322E6BEC26578E45B736.mlw
sha1: 7f842eb80b2183ee56c3bd345585637c9e7d6af4
sha256: 7cb9c8afe1e92c7f70ce9f5fdd8958aa960e868e4d916209d71714456a39acd7
sha512: 4bd0d60c37de85b1acac1df72178e6d0ec4fcd300a46c3a6dca015b70c1cca1219344df29fbbd141925f806d3742b477f14f743faa775ae24d2cdef2851d1cb8
ssdeep: 6144:OYg+ndEfe4PkjkPkI+lRtyJvwMfbOHfhuC:djefXP4IqR0Jvbk4C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/TrojanDropper.Agent.RYA also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.3654
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.GandCrab.Gen.2
CylanceUnsafe
ZillyaDropper.Agent.Win32.373274
SangforWin.Packed.Gandcrab-6552923-4
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056e9401 )
K7AntiVirusTrojan ( 003e58dd1 )
CyrenW32/S-15f730e0!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RYA
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
BitDefenderTrojan.Ransom.GandCrab.Gen.2
NANO-AntivirusTrojan.Win32.TrjGen.fcocpf
ViRobotTrojan.Win32.GandCrab.Gen.A
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
TencentMalware.Win32.Gencirc.10b3e14a
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
SophosMal/Generic-R + Mal/Agent-AUL
ComodoTrojWare.Win32.Chapak.GFD@7o3yhi
F-SecureHeuristic.HEUR/AGEN.1126869
BitDefenderThetaGen:NN.ZexaF.34608.tuX@aihx@Nl
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.THFOAAH
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.d816d0c95e63322e
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.ajgn
AviraHEUR/AGEN.1126869
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/GandCrypt.PVR!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
AegisLabTrojan.Win32.GandCrypt.tpxW
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeeGenericRXGH-ZE!D816D0C95E63
MAXmalware (ai score=99)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.THFOAAH
RisingTrojan.Crypto!8.364 (CLOUD)
YandexTrojan.GenAsa!9rdjJm7edb0
IkarusTrojan-Ransom.GandCrab
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.9b6

How to remove Win32/TrojanDropper.Agent.RYA?

Win32/TrojanDropper.Agent.RYA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment