Trojan

What is “Win32/TrojanDropper.Agent.SPU”?

Malware Removal

The Win32/TrojanDropper.Agent.SPU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.SPU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/TrojanDropper.Agent.SPU?


File Info:

name: BFBFA1E4E3DFC8DED42C.mlw
path: /opt/CAPEv2/storage/binaries/cc6b8c6ca01bc6b8a91d5e5153cef527a0f22ebb734c4f665eb854c3272d1b08
crc32: 2663F94C
md5: bfbfa1e4e3dfc8ded42cdbe6d2fcd459
sha1: e10f8f0652a88ce912a5b4cc9f83f1811759c891
sha256: cc6b8c6ca01bc6b8a91d5e5153cef527a0f22ebb734c4f665eb854c3272d1b08
sha512: fb7802cf33f534e4b2a033a6702515fb84f4e0479473209b4932f901eb68b095def0e88d74c6d05a5f04eb8e9d760ad3c9a27fa28b7a44245dedd08a84d973c6
ssdeep: 98304:iX4fRCKFKUuUeT7LlYDnejYeoZa4A+8isoMmuAzUZUP7SDKUhtcGCyTLGJANFI2:4QMoKlUeTHlRjYTZa4psmuTocKUTCamq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC561227B2A4A13EC06927354577A4509DFBF7ADF412BE1626E4CC8DCF660C00EFA625
sha3_384: 9c96f8c3a4c5392f8a77b3b80aaf93dd82f370b12795c6682359890c6ca28282de9d453144113ceecd785fd8c1f5b905
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-04-27 08:22:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: ConsoleApp Setup
FileVersion: 1.0.0.0
LegalCopyright:
OriginalFileName:
ProductName: ConsoleApp
ProductVersion: 1.0.0.0
Translation: 0x0000 0x04b0

Win32/TrojanDropper.Agent.SPU also known as:

LionicTrojan.Win32.Bitser.a!c
McAfeeArtemis!BFBFA1E4E3DF
MalwarebytesTrojan.Dropper
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanDownloader:Win32/Bitser.c1cf8766
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDropper.Agent.SPU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Bitser.cor
TencentWin32.Trojan-downloader.Bitser.Pkhj
GridinsoftRansom.Win32.Sabsik.sa
AhnLab-V3Malware/Win.Generic.C4802126
TrendMicro-HouseCallTROJ_GEN.R002H0CL221
YandexTrojan.DL.Bitser!9TRFXYwe3bE
MaxSecureTrojan.Malware.121218.susgen
FortinetPossibleThreat.MU

How to remove Win32/TrojanDropper.Agent.SPU?

Win32/TrojanDropper.Agent.SPU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment