Trojan

Win32/TrojanDropper.Agent.STR removal guide

Malware Removal

The Win32/TrojanDropper.Agent.STR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.STR virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/TrojanDropper.Agent.STR?


File Info:

name: 31E56460420DD8CA3C8B.mlw
path: /opt/CAPEv2/storage/binaries/05bcb89ec50ef3091b4c1ef37afd0723ba5dd2f2ae2b5c059005e7490e58796e
crc32: 127373FC
md5: 31e56460420dd8ca3c8b48a975fba62f
sha1: 927f85fa734873851dfe4eb3fbd49da2d9a384c4
sha256: 05bcb89ec50ef3091b4c1ef37afd0723ba5dd2f2ae2b5c059005e7490e58796e
sha512: 0b40f9b34d32ed74c0e458215df329f477fdcfd6a5d4f00f76b6a76aac5edc6fa3db346581b0725f4a53cbbbd5640e15b4e870a3d9400e8a78f859b63534c0dc
ssdeep: 12288:cz/kaoDAqkOdmxluIOELtJbAb5gqJ1KZ0WvsxnUX63iz/XPvbG+O/r0G:hawkxxl/3Jk9emWvsxnUXzPjG+srT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AF423E5E4411F8AF45A4A35489DE96C6BC39CA774A2734F2D00BF8CF0723D5A5C2CA6
sha3_384: d53bd634e8baba7aaf3f138f782d788fe7fc83a04552409011da2c3fff44949de9a301b4e19b5f451b9b9a4f18560ea7
ep_bytes: 60be00105f008dbe0000e1ff57eb0b90
timestamp: 2024-03-20 02:05:11

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 永恒之绿
ProductVersion: 1.0.0.0
CompanyName: 永恒之绿
LegalCopyright: 永恒之绿 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Win32/TrojanDropper.Agent.STR also known as:

LionicTrojan.Win32.Convagent.b!c
MicroWorld-eScanGen:Variant.Fragtor.486125
FireEyeGeneric.mg.31e56460420dd8ca
ALYacGen:Variant.Fragtor.486125
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.36802.SmKfaiAd4Uib
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.STR
APEXMalicious
CynetMalicious (score: 100)
AlibabaTrojanDropper:Win32/CoinMiner.b2671fca
NANO-AntivirusTrojan.Win32.KillProc.exumyt
ZillyaDropper.Daws.Win32.26782
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Krypt
AviraTR/Drop.Agent.kexhz
Antiy-AVLRiskWare/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Fragtor.D76AED
GoogleDetected
AhnLab-V3Malware/Win.Generic.R560075
VBA32Trojan.Agent
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
TencentMalware.Win32.Gencirc.10bf1074
YandexTrojan.GenAsa!DkD2/bGw7+g
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
Cybereasonmalicious.0420dd
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Fragtor

How to remove Win32/TrojanDropper.Agent.STR?

Win32/TrojanDropper.Agent.STR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment