Trojan

Win32/TrojanDropper.Agent.SEZ malicious file

Malware Removal

The Win32/TrojanDropper.Agent.SEZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.SEZ virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/TrojanDropper.Agent.SEZ?


File Info:

name: ADCA2A748F234E58906B.mlw
path: /opt/CAPEv2/storage/binaries/620341cb8dd99eb0b1220bad5c7846d4f216bd2c277abca25851b6a52d4ae710
crc32: 3971D5A7
md5: adca2a748f234e58906bbb226b0b91a9
sha1: 5ecd2c2c7abe4ad43712d06272e2a645fce3c907
sha256: 620341cb8dd99eb0b1220bad5c7846d4f216bd2c277abca25851b6a52d4ae710
sha512: 05659584833632d765bb5edd9563b57a11273443e731d1ca6a611bdb79b429821291fbf8788480162e3d3f9bcdcf055e92e7bad38e158e162d17c2c60fb18c68
ssdeep: 24576:KmgnvKp+v6DNITLj3ZjJ62fUiYgOCX4lAVSGQTgoFh7ZF9ero:Tgnv1v6DNITfJjA2fU0OCfSGpoVeE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC45125D7A9093F2EC4409706665CBEB2C79BDB5A752DEC333D666089D302C0A632B73
sha3_384: 79e36e88b0602f645b92569b256a05c441cc1647c86b5eccb2f065e4fb689e3cb2727c415036ee54d9d8617de3baa631
ep_bytes: e85d3e0000e97ffeffff3b0d38515200
timestamp: 2013-09-10 06:38:32

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Win32/TrojanDropper.Agent.SEZ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.43120
MicroWorld-eScanGen:Variant.Zusy.297570
FireEyeGeneric.mg.adca2a748f234e58
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericR-EOA!ADCA2A748F23
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.297570
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004e144e1 )
K7GWTrojan ( 004e144e1 )
BitDefenderThetaGen:NN.ZexaF.36738.mr0@aqkYF2ni
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SEZ
APEXMalicious
ClamAVWin.Malware.Bskd-9753126-0
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Zusy.297570
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10bb7317
EmsisoftGen:Variant.Zusy.297570 (B)
F-SecureHeuristic.HEUR/AGEN.1312982
ZillyaDropper.Agent.Win32.261082
TrendMicroTrojan.Win32.SALGOREA.SMAL01
Trapminemalicious.high.ml.score
SophosTroj/Agent-BAII
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
GDataGen:Variant.Zusy.297570
JiangminBackdoor.Generic.ayej
GoogleDetected
AviraHEUR/AGEN.1312982
VaristW32/Risk.BXYS-5967
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Salgorea.RHG@7yqza3
ArcabitTrojan.Zusy.D48A62
ZoneAlarmHEUR:Backdoor.Win32.Salgorea.vho
MicrosoftTrojan:Win32/Salgorea.VRR!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369448
Acronissuspicious
VBA32Trojan.Salgorea
ALYacGen:Variant.Zusy.297570
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SALGOREA.SMAL01
RisingTrojan.Agent!1.B332 (CLASSIC)
YandexTrojan.GenAsa!ykJlBo8qQNU
IkarusTrojan.Win32.Salgorea
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RHG!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/TrojanDropper.Agent.SEZ?

Win32/TrojanDropper.Agent.SEZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment