Trojan

Win32/TrojanDropper.Agent.SPI malicious file

Malware Removal

The Win32/TrojanDropper.Agent.SPI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.SPI virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Win32/TrojanDropper.Agent.SPI?


File Info:

name: 699BF1754023167A0E7E.mlw
path: /opt/CAPEv2/storage/binaries/32811677dda02f7c3d1fc549009c79218e419c1b9d59634e14bc5de452078883
crc32: CEEF3FFC
md5: 699bf1754023167a0e7e69d7083b357d
sha1: 77a5e9538110c133d702cec41e93c97b1d645aa1
sha256: 32811677dda02f7c3d1fc549009c79218e419c1b9d59634e14bc5de452078883
sha512: b154de7005cf3a6a6a53fe0fed156d4e463e670af620d80cbc00ae1b812ab0d438c271b8de7ce13df6a66a7f642180e19c09033f28428e86088563755df9ed31
ssdeep: 1536:RSZAreJSOv1gTRFtBbmfhKKpP7iFmZmZoPgHcwVX4U:RSZAjOAXXbOymMZVJXD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122638D13BB9186BDD23506315DE5E2B940BBF6369B094B4BB388430E1D745D4EF22B4B
sha3_384: bb0ac8949e01c500d88f884f6de1c7ae6d4c5d982a958f214f4559ebf6afa4d2257f3dca497ca62f141db82a20bd5435
ep_bytes:
timestamp: 2021-10-28 09:01:51

Version Info:

0: [No Data]

Win32/TrojanDropper.Agent.SPI also known as:

CrowdStrikewin/malicious_confidence_90% (W)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SPI
APEXMalicious
SophosGeneric PUA HH (PUA)
ComodoHeur.Corrupt.PE@1z141z3
McAfee-GW-EditionArtemis!Trojan
GridinsoftTrojan.Win32.Agent.oa
MicrosoftProgram:Win32/Uwamson.A!ml
RisingTrojan.DotNetLoader!1.DA67 (CLASSIC)

How to remove Win32/TrojanDropper.Agent.SPI?

Win32/TrojanDropper.Agent.SPI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment