Malware

Dropper.167 (B) removal

Malware Removal

The Dropper.167 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropper.167 (B) virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropper.167 (B)?


File Info:

name: A3067579BDECC1FBA08D.mlw
path: /opt/CAPEv2/storage/binaries/4a22dfc77c81d1077629813e404de32cc8b40500ee5df37c44fb1420044624a5
crc32: CE64EF7E
md5: a3067579bdecc1fba08d38625ecd479c
sha1: 1c6fe00c97236ed3bc62edeb61bfc6589a42017c
sha256: 4a22dfc77c81d1077629813e404de32cc8b40500ee5df37c44fb1420044624a5
sha512: 2ea5554d2ff4bbd4fb50146e5d5660208948b356454048d66ff7675a42d099764f944716ddddc6c88608c5e3ad22e37dec11f7e53c1b43f75288a988dedcf5fe
ssdeep: 49152:aTjsXEY+EAAI1WCMIvSUB8ciOXTtorhKo2bVu32tnHDaea+w6DW1FFdeiJ:K8EkAAQMIvFicTWrXYMmtnjhsF/J
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DDA53389F013DBB1F6A7063898F7EAAF593DE906CB146C9ADF0CE557A462707205E310
sha3_384: 39d43b7616571fe95ebf6383d0a0216efc90a912d74a59e98aea443bf349d2be44a52343fd53c2d8388af8c63462b694
ep_bytes: 83ec0cc70598d5410000000000e89e84
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName:
ProductName:
ProductVersion: 1, 1, 6, 5,
InternalName: IntelGFX
OriginalFilename: IntelGFX.exe
FileVersion:
FileDescription:
LegalCopyright:
LegalTrademarks:
Translation: 0x0409 0x04b0

Dropper.167 (B) also known as:

BkavW32.Common.D18D2345
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Dropper.167
FireEyeGen:Variant.Dropper.167
SkyhighBehavesLike.Win32.HLLP.vc
McAfeeArtemis!A3067579BDEC
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Dropper.167
SangforDropper.Win32.Agent.Vj4z
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Dropper.167
AvastWin32:Malware-gen
EmsisoftGen:Variant.Dropper.167 (B)
MAXmalware (ai score=80)
ArcabitTrojan.Dropper.167
GDataGen:Variant.Dropper.167
ALYacGen:Variant.Dropper.167
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R011H09L623
MaxSecureTrojan.Malware.10786119.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Dropper.167 (B)?

Dropper.167 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment