Malware

Should I remove “Dropper.1”?

Malware Removal

The Dropper.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropper.1 virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropper.1?


File Info:

name: 1B05E1B4827BFAB2E33A.mlw
path: /opt/CAPEv2/storage/binaries/b820fbacc69b1a9834ac875698a7aef14230f1c92fa6489bdf3d46c2890cbf6b
crc32: 5E9685CD
md5: 1b05e1b4827bfab2e33a9a43b366f8ba
sha1: 78785948db4ee15f3780a7bf59809e13374b3e51
sha256: b820fbacc69b1a9834ac875698a7aef14230f1c92fa6489bdf3d46c2890cbf6b
sha512: e1daf122f3405327e44f97025b272bd146c03ced64992610eab2a00a7f204fef3d492c39a63b11b6bb5942812c24b3ab416351cd3425fe4274ad88b9f2d4f34f
ssdeep: 12288:JBG8KleJocFYE1nm2q/u45KX0bgcq0em/SQoz/N:3G8JqQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAC4D7456A9A91C3F03214743896B7A31D3BF437AEC48F72222E530AEB6ED06155EF4D
sha3_384: fd93eb1f87b55e759408ae9a2f023a2013912c52a51b288550079b2081b6f140f796b4b98b780667b23c58c05fb328a4
ep_bytes: 558bec6aff68988f4100683c6a400064
timestamp: 2009-12-18 10:54:09

Version Info:

Comments:
CompanyName: Jling Studio
FileDescription: 精灵快捷栏主程序
FileVersion: 0.1.8.0
InternalName: JlingQuick
LegalCopyright: 版权所有 (C) 2010
LegalTrademarks:
OriginalFilename: JlingQuick.EXE
PrivateBuild:
ProductName: JlingQuick应用程序
ProductVersion: 0.1.8.0
SpecialBuild:
Translation: 0x0804 0x04b0

Dropper.1 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.StartPage.39161
MicroWorld-eScanGen:Variant.Dropper.1
FireEyeGeneric.mg.1b05e1b4827bfab2
CAT-QuickHealTrojanDropper.Injector.B4
ALYacGen:Variant.Dropper.1
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDropper.Inegery.Win32.65
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 001579ea1 )
K7GWTrojan ( 001579ea1 )
Cybereasonmalicious.4827bf
BitDefenderThetaGen:NN.ZexaF.36318.Jq1@a4c!S4fb
CyrenW32/StartPage.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Inject.aadjf
BitDefenderGen:Variant.Dropper.1
NANO-AntivirusTrojan.Win32.Inegery.btpgy
AvastWin32:DropperX-gen [Drp]
RisingTrojan.Clicker.Win32.Agent.fly (CLASSIC)
SophosTroj/Inject-EBY
F-SecureTrojan.TR/StartPage.OH
VIPREGen:Variant.Dropper.1
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Dropper.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Inegery.q
AviraTR/StartPage.OH
MAXmalware (ai score=85)
Antiy-AVLTrojan[Dropper]/Win32.Inegery
XcitiumTrojWare.Win32.TrojanDropper.Inegery.A@23kosv
ArcabitTrojan.Dropper.1
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmTrojan.Win32.Inject.aadjf
GDataGen:Variant.Dropper.1
GoogleDetected
AhnLab-V3Win-Trojan/Startpage3.Gen
Acronissuspicious
McAfeeStartPage-LZ
VBA32BScope.Trojan.StartPage
Cylanceunsafe
PandaTrj/Dropper.JTH
TencentMalware.Win32.Gencirc.10b89b0f
YandexTrojan.GenAsa!EBMb6TJsRt4
IkarusTrojan-Downloader.Agent2
MaxSecureDropper.Inegery.l
FortinetW32/Generic.AC.86026
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Dropper.1?

Dropper.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment