Trojan

TrojanDropper:Win32/Twores removal tips

Malware Removal

The TrojanDropper:Win32/Twores is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Twores virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanDropper:Win32/Twores?


File Info:

name: 2E5FD64DC957FE3BD07E.mlw
path: /opt/CAPEv2/storage/binaries/1ac2d43cac38513786621b5446dfb0125f6ba887a5f60cf6b10f58ad8b285f25
crc32: ECEDBB2D
md5: 2e5fd64dc957fe3bd07ee409b8515e05
sha1: 1b77ff83c1f684865256377c5fc4e7c3d144fd30
sha256: 1ac2d43cac38513786621b5446dfb0125f6ba887a5f60cf6b10f58ad8b285f25
sha512: 2be567b12d461f5f9aa9361fd40f504753d716489e039622cd2dc5688a693db114cf5b9f9c6932c1a392067036346435b97e4457f9e98d9437b3157fcc6d56a3
ssdeep: 12288:cjbnK4od6iHioeIVMSK4NYt4ZPuHv+gsWmlek0N2g2w3gO0U8fm5cnKgz8RUTV53:kZtciobiM6sWmPB8gO0XfBKoTV5n1lT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE45BF53F281D476C2290539CC1B96FC5A66BD122D15AC0B3AF83F0E9F7A3C1392665B
sha3_384: a298be6d2ebb37b68867c3ac339c8bca6d61632bcd64c6ebb7fb69254ea085d13ef0876cc628cfabfc0c0da0fd1ad355
ep_bytes: 558bec83c4f053b8e4304700e8072df9
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanDropper:Win32/Twores also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Graftor.104362
FireEyeGen:Variant.Graftor.104362
SkyhighBehavesLike.Win32.ObfuscatedPoly.th
ALYacGen:Variant.Graftor.104362
MalwarebytesBinder.Trojan.Dropper.DDS
VIPREGen:Variant.Graftor.104362
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Variant.Graftor.104362
K7GWTrojan ( 7000000f1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Binder.NAD
APEXMalicious
ClamAVWin.Dropper.Agent-42975
KasperskyVirTool.Win32.Adrenaline.e
AlibabaTrojanDropper:Win32/Adrenaline.3c35eb4b
NANO-AntivirusTrojan.Win32.PcClient.dleljw
RisingMalware.Undefined!8.C (TFE:5:gnJcTZFxcSR)
SophosMal/Banker-AA
BaiduWin32.Trojan-Dropper.Binder.h
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.Click.48789
TrendMicroBKDR_PCCLIEN.OP
EmsisoftGen:Variant.Graftor.104362 (B)
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraDR/Delphi.Gen
VaristW32/Tool.AYKL-1057
Antiy-AVLHackTool[VirTool]/Win32.Joiner
KingsoftWin32.Hack.PcClient.agu
MicrosoftTrojanDropper:Win32/Twores.gen
XcitiumMalware@#old3gjpyrfog
ArcabitTrojan.Graftor.D197AA
ZoneAlarmVirTool.Win32.Adrenaline.e
GDataGen:Variant.Graftor.104362
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Delphiless.R277588
McAfeeArtemis!2E5FD64DC957
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Download
PandaGeneric Malware
TrendMicro-HouseCallBKDR_PCCLIEN.OP
TencentMalware.Win32.Gencirc.10be3d2b
YandexTrojan.GenAsa!A1A+ugJf/Ss
IkarusBackdoor.Win32.PcClient
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dropper.DAH!tr
AVGWin32:Agent-QKX [Drp]
AvastWin32:Agent-QKX [Drp]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove TrojanDropper:Win32/Twores?

TrojanDropper:Win32/Twores removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment